I have been waiting for the security audit report since the first time it was mentioned. Now that it is out i feel a little disappointed that there are no real intentional risks
Why would you be disappointed that there's nothing wrong with it? Why would you be hoping that the program millions use to protect their sensitive information was broken?
I'm not disappointed by a fairly uneventful report, but quite honestly, I'm always a little bit worried when nothing horrible is discovered in the course of testing.
It's not that I want there to be bugs, but that in a large enough codebase, there's always a game-over bug -- major information leakage, arbitrary code exec, whatever. As a security consultant, I'm always more confident in a test when I find a horrendous bug than when I don't; I know that bug will be fixed, and it makes me feel like the test is more complete, even if I know full well that I did the test to the absolute best of my abilities regardless.
I've heard similar sentiments from most testers I know.
I'm not OP, but I suspect it's a bit like watching a hyped sporting event. There's a build up, lots of discussion, some naysayers and the tech equivalent of trash talking. In the end you sort of expect something more exciting than what we got. It's sort of like watching the favorites secure a clinical win in the Superbowl. It's ok, but no one's going to be talking about it for years to come.
That said, as a Truecrypt user, this is good. I don't have the technical expertise to understand truecrypt myself, but a second set of eyes (and all the eyes watching that second set) make me more comfortable. Follow standard security recommendations and you're pretty safe.