Live data from Hacker News

Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

techspot.com

51–60 of 280 posts

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#51
This doesn't sound bitlocker specific, sounds more like a login bypass. If you rely on TPM without PIN then it gets decrypted automatically. This should be fine normally as attackers shouldn't be able to get past login screen. But this exploit shows a way allegedly to get a unrestricted shell in the recovery environment.

The researcher claims a way to bypass PIN too but hasn't revealed it.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#52
post #4

Maybe I’m an outlier but I don’t want my drives encrypted at all. I rather have all my data be accessible if things go catastrophic, I.E. having to pull the drive out of a broken computer and put it in another computer to access the files. I just want it to be plug and play.

So long as you've backed up the key you can fairly easily decrypt on any machine.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#53

Title sounds conspiratorial, but it lines up well with the controversy around TrueCrypt's discontinuation which, I believe, specifically called out BitLocker as an alternative to use in future.

You're probably thinking of VeraCrypt, which is a fork of TrueCrypt. I don't think BitLocker is related.

[dead]

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#54

Seems this traces back almost a week, from Nightmare-Eclipse who is the researcher who found this: Tuesday, 12 May 2026 - "Here are the links, yes, two vulnerabilities this time [YellowKey] [GreenPlasma] [...] Next patch tuesday will have a big surprise for you Microsoft" Wednesday, 13 May 2026 - "I can't wait when I will be allowed to disclose the full story, I think people will find my crashout very reasonable and…

I read it as the author is / was going through the vulnerability disclosure process with Microsoft and they're annoyed for unclear reasons and decided to publicly disclose, rather than being an insider.

How would that leave them homeless?

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#55
Well I doubt anyone would be surprised with a backdoor in MS product, there have been many of them already, I frankly doubt anyone with "disk encryption" on Windows would think that it's NSA-proof (or script-kiddy clever, as shown in this article :))

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#56
post #17

Earlier quoted context omitted.

Hey now, I use rot13 on my sticky notes.

Gotta bump that encryption up - rot26 is twice as secure.

Secure rot* variants require UTF-8 and mappings that shift characters between {1,2,3,4}-byte encoded-character-sizes. That varies the message length, which prevents any message-length or traffic analysis.

The Snowden leaks revealed that the NSA is flummoxed on how to tackle variable character lengths. However, they've cracked rot26 using custom ASIC supercomputers, so it should be considered insecure even though it's twice as good as rot13.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#57
> The vulnerability may also work without a USB drive if the FsTx files are copied to the Windows EFI partition and the encrypted disk is temporarily disconnected from the system. After placing the FsTx folder, an attacker would need to reboot a BitLocker-protected machine, enter the Windows Recovery Environment, and follow a specific sequence of inputs.

At the point where you're able to mount the EFI partition and effectively modifying the bootloader, it's game over anyway - just run `manage-bde -unlock`, you already have to be root to mount the EFI partition.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#59
post #36
post #32

"Security professionals generally recommend avoiding reliance on any single encryption system and instead evaluating well-reviewed full-disk encryption alternatives such as VeraCrypt". If they put a backdoor into FDE it would make more sense to advise people to stop using windows at all and using Linux instead. If they put a backdoor in FDE you can be sure there is not just one backdoor in the operating system itself…

I don't use Microsoft products generally but not with even with your computer would I run VeraCrypt.

Curious to see this take from you! I followed TrueCrypt for years, but always thought it was very strange that they were anonymous, and then the mysterious shutdown happened, and I have no idea what to make of VeraCrypt. It's been in my "possibly good, but too many weird flags around the whole project" bucket.

Anything in particular that makes you wary? I'm aware of the 2016 and 2020 audits (https://ostif.org/the-veracrypt-audit-results/ is the 2016 one, I believe), but those seemed to suggest things were getting better over time. Curious what other signals to look for.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#60

Seems this traces back almost a week, from Nightmare-Eclipse who is the researcher who found this: Tuesday, 12 May 2026 - "Here are the links, yes, two vulnerabilities this time [YellowKey] [GreenPlasma] [...] Next patch tuesday will have a big surprise for you Microsoft" Wednesday, 13 May 2026 - "I can't wait when I will be allowed to disclose the full story, I think people will find my crashout very reasonable and…

Can’t wait to read the blogpost of what have truly happened and motivated this person to expose M$ like this

[flagged]
Post reply on HN