Live data from Hacker News

Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

techspot.com

211–220 of 280 posts

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#211

Earlier quoted context omitted.

Good luck convincing a HR automaton not looking at your resume for the job unposting of that.

Come on, with these skills you could convince someone to give you a job if you’re on the streets otherwise. You might not be a senior engineer in the exact thing you want but you won’t be on the streets.

It's not about your skills. It's about how well you can play the HR metagame. This inversely correlates with actual job skills.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#212
post #88

Better writeup: https://infosec.exchange/@wdormann/116565129854382214 The published exploit doesn’t affect Bitlocker with a PIN, without which Bitlocker isn’t secure anyway. The original author claims they have an exploit that also works with a PIN, but hasn’t provided any proof of that.

Does your company require the pin? Or more importantly, does the company that your company pays for Cyber insurance require the pin? I have never seen a company where they require the pin for bitlocker.

It is a mandatory requirement for many Department of Defense Contractors. It matters what systems your company interacts with here creating the requirement. The bigger ones just mandate it to save headaches.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#213
post #172

Earlier quoted context omitted.

Many brilliant people have serious mental health issues that preclude their ability to regulate their emotions and act maturely in serious situations e.g. responsible vulnerability disclosure. I've watched genius-level IQ people get fired time and again because they don't know how to work with others at a basic kindergarten level.

There is, sadly, no place for non-standard ICs in corpos nowadays. HR will enforce that.

IC = Independent contractor (I assume?)

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#214
post #172

Earlier quoted context omitted.

There is, sadly, no place for non-standard ICs in corpos nowadays. HR will enforce that.

Yeah I'm getting a lot of pressure to be a "team player" lately. I've told them over and over I'm not capable of that and that has never been a problem before. But we have a hipster new VP who is really pushy and wants to generalise everything.

> I've told them over and over I'm not capable of that

I can relate and empathize. And also provide this suggestion based on my own similar experience: if you can't provide evidence (e.g. doctor's diagnosis) that you are "special" or "not capable of that", then they don't have to care and will take steps to force you out. I wish you all the best.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#215

Title sounds conspiratorial, but it lines up well with the controversy around TrueCrypt's discontinuation which, I believe, specifically called out BitLocker as an alternative to use in future.

Why is 'conspiratorial' posed as a prime facie _bad thing_ to posit?

Mental inertia. It used to be a bad thing to theorize conspiracies without evidence, but now we actually have evidence of so many conspiracies similar to this that it's probable there are lots more.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#216

Earlier quoted context omitted.

Good luck convincing a HR automaton not looking at your resume for the job unposting of that.

Come on, with these skills you could convince someone to give you a job if you’re on the streets otherwise. You might not be a senior engineer in the exact thing you want but you won’t be on the streets.

Convincing someone, especially an HR person, has very little to do with computer skills.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#217

Earlier quoted context omitted.

Or use something like veracrypt which is opensource

Don't be so sure. Veracrypt is a fork of Truecrypt, which was famously shuttered after security rumours started spreading - all the way to NSA interventions aimed at the developers. One rumour even said they intentionally shut it down to prevent a possible backdoor compromise. Popular encryption tools for public use will always be priority targets for three letter agencies. And there's more than enough legal leeway h…

In my humble opinion US TLAs don't need to touch Veracrypt at all. They are already in Windows, so keymaterial exfiltration is probably a child's play for them.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#218
post #213
post #172

Earlier quoted context omitted.

There is, sadly, no place for non-standard ICs in corpos nowadays. HR will enforce that.

IC = Independent contractor (I assume?)

Individual contributor i.e., non-management

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#219
post #54

Earlier quoted context omitted.

How would that leave them homeless?

Many brilliant people have serious mental health issues that preclude their ability to regulate their emotions and act maturely in serious situations e.g. responsible vulnerability disclosure. I've watched genius-level IQ people get fired time and again because they don't know how to work with others at a basic kindergarten level.

Reporting wrongdoing to the ones doing it doesn't work. Perhaps they relied on Microsoft a bit too much for their livelihood and are just beginning to reevaluate their decisions. It's not so rare for brilliant people to live a life of the mind and not pay enough attention to their material conditions. But defining that as "serious mental health issues" is such a cheap shot.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#220
post #151

Seems this traces back almost a week, from Nightmare-Eclipse who is the researcher who found this: Tuesday, 12 May 2026 - "Here are the links, yes, two vulnerabilities this time [YellowKey] [GreenPlasma] [...] Next patch tuesday will have a big surprise for you Microsoft" Wednesday, 13 May 2026 - "I can't wait when I will be allowed to disclose the full story, I think people will find my crashout very reasonable and…

Previously discussed numerous times on HN, like: https://news.ycombinator.com/item?id=48130519 Whether this is a backdoor or not boils down to whatever your usual proclivities about "bug or backdoor" are; it's not like "if microsoft = 1 hack bitlocker" like the tech press seem to love to report. This is a bug in the NTFS transaction log replay functionality in the Windows Recovery Environment WinRE, where it will rea…

This is the most succinct, plain-English explanation I've seen to date. Thank you for posting this.
Post reply on HN