The researcher claims a way to bypass PIN too but hasn't revealed it.
Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
51–60 of 280 posts
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#52Maybe I’m an outlier but I don’t want my drives encrypted at all. I rather have all my data be accessible if things go catastrophic, I.E. having to pull the drive out of a broken computer and put it in another computer to access the files. I just want it to be plug and play.
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#53Title sounds conspiratorial, but it lines up well with the controversy around TrueCrypt's discontinuation which, I believe, specifically called out BitLocker as an alternative to use in future.
You're probably thinking of VeraCrypt, which is a fork of TrueCrypt. I don't think BitLocker is related.
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#54Seems this traces back almost a week, from Nightmare-Eclipse who is the researcher who found this: Tuesday, 12 May 2026 - "Here are the links, yes, two vulnerabilities this time [YellowKey] [GreenPlasma] [...] Next patch tuesday will have a big surprise for you Microsoft" Wednesday, 13 May 2026 - "I can't wait when I will be allowed to disclose the full story, I think people will find my crashout very reasonable and…
I read it as the author is / was going through the vulnerability disclosure process with Microsoft and they're annoyed for unclear reasons and decided to publicly disclose, rather than being an insider.
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#55Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#56Earlier quoted context omitted.
Hey now, I use rot13 on my sticky notes.
Gotta bump that encryption up - rot26 is twice as secure.
The Snowden leaks revealed that the NSA is flummoxed on how to tackle variable character lengths. However, they've cracked rot26 using custom ASIC supercomputers, so it should be considered insecure even though it's twice as good as rot13.
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#57At the point where you're able to mount the EFI partition and effectively modifying the bootloader, it's game over anyway - just run `manage-bde -unlock`, you already have to be root to mount the EFI partition.
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#58Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#59"Security professionals generally recommend avoiding reliance on any single encryption system and instead evaluating well-reviewed full-disk encryption alternatives such as VeraCrypt". If they put a backdoor into FDE it would make more sense to advise people to stop using windows at all and using Linux instead. If they put a backdoor in FDE you can be sure there is not just one backdoor in the operating system itself…
I don't use Microsoft products generally but not with even with your computer would I run VeraCrypt.
Anything in particular that makes you wary? I'm aware of the 2016 and 2020 audits (https://ostif.org/the-veracrypt-audit-results/ is the 2016 one, I believe), but those seemed to suggest things were getting better over time. Curious what other signals to look for.
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#60Seems this traces back almost a week, from Nightmare-Eclipse who is the researcher who found this: Tuesday, 12 May 2026 - "Here are the links, yes, two vulnerabilities this time [YellowKey] [GreenPlasma] [...] Next patch tuesday will have a big surprise for you Microsoft" Wednesday, 13 May 2026 - "I can't wait when I will be allowed to disclose the full story, I think people will find my crashout very reasonable and…
Can’t wait to read the blogpost of what have truly happened and motivated this person to expose M$ like this