OSXCrypt – a TrueCrypt for MacOSX

For some time MacOSX has lacked a top quality, open source, plausible-deniability encryption solution. TrueCrypt is the obviously leader here, but is incompatible with OSX – you could try and run the Windows version in a VM, but that’s not an option for serious day to day use; a native version is infinitely preferable.

Seems like the drought has broken, however, with the latest version of OSXCrypt, which looks very much like it will become the encryption client for MacOSX.

While OSX has shipped for some time with some built-in encryption capability, namely encrypted disk images and FileVault, these have severe problems in that they support only a single internal password & volume, and thus provide no plausible deniability. There is no point encrypting files if you can be arrested for not divulging your password – unless it’s to simply divert casual 3rd party inspection as in the “computer repair shop” scenario. Until now the only case I could think of that would be useful for, say, an airport check would be to run a third, FileVault-encrypted account and simply claim it was for your “roommate” or what not and you didn’t know the password. Use of Truecrypt solves all these problems – one password will open one internal volume, another will open another, and there is absolutely no way to prove the second’s existence.

There is also the very real possibility that Apple retains “escrow” keys for all encryption schemes implemented in MacOSX. Without the possibility of source code review by experts, it’s impossible to say. Microsoft certainly backdoors its encryption (NSAKEY, anyone?).

The source code is available and an alpha is available for testing. Command line only for now, a GUI is on the way. Finally, a real encryption solution for the Mac! Great news for the ultra-paranoid .. like me ..

UPDATE: a tutorial is available (in german) here.

Tags:

One Response to “OSXCrypt – a TrueCrypt for MacOSX”

  1. OsxCrypt Says:

    Thanx for the writeup, we really appreciate some spotlight on our project…

    The aim of this is not to be THE encrypting software, but, better, THE ENCRYPTION PLATFORM on which tons of developers can attach their genius to provide better coding, better algorithms, better UI…

    As you stated an UI is on the way, even if it is not the primary concern…

    We’ll kepp all of you updated and you can sign up the Devel ML (devel at osxcrypt dot org).

    Happy Hacking!

    The Core

Leave a Reply

You may edit your comment for up to 30 minutes after submission.