back
3 comments
My money is on the site being compromised. If this were a legit, why would they be doing a 302 redirect to a SourceForge page instead of keeping the notice it under their own domain? Also, if TC only existed for XP users, why even have a *nix version? None of this makes sense in the context of this being a legitimate notice.
truecrypt.org does a redirect to this sourceforge page, so perhaps it is the DNS that got hijacked, and not truecrypt website itself.

I don't remember TC ever being hosted on SF, so I think this is a bad redirect...

On the other hand, SourceForge lists the project as having been created in 2004: http://sourceforge.net/projects/truecrypt/
The SF account could have been compromised too.
Certainly, it just makes it less suspect that it’s on SourceForge at all. (Unless SourceForge lets you rename projects? Then it could be an old placeholder project that’s been renamed to truecrypt.)