Live data from Hacker News

YellowKey Bitlocker Bypass Vulnerability

github.com

11–20 of 22 posts

Re: YellowKey Bitlocker Bypass Vulnerability

#11
post #6
post #5

How is this a backdoor if one of the steps is to reboot the system while holding down SHIFT? To boot in the first place, the drive needs to be unlocked.

Most users have it unlocked by TPM only as that is the default Microsoft configuration - you then reboot into windows recovery, yes if windows recovery is disabled or if bitlocker requires a startup pin then this is mitigated.

"No, TPM+PIN does not help, the issue is still exploitable regardless, I asked myself this question, can it still work in a TPM+PIN environment ? Yes it does, I'm just not publishing the PoC, I think what's out there is already bad enough."

https://deadeclipse666.blogspot.com/2026/05/were-doing-silen...

Re: YellowKey Bitlocker Bypass Vulnerability

#14
post #11
post #6

Earlier quoted context omitted.

Most users have it unlocked by TPM only as that is the default Microsoft configuration - you then reboot into windows recovery, yes if windows recovery is disabled or if bitlocker requires a startup pin then this is mitigated.

"No, TPM+PIN does not help, the issue is still exploitable regardless, I asked myself this question, can it still work in a TPM+PIN environment ? Yes it does, I'm just not publishing the PoC, I think what's out there is already bad enough." https://deadeclipse666.blogspot.com/2026/05/were-doing-silen...

Interesting. If TPM+PIN does not help, then what stands between Bitlocker and TPM unsealing the key?

Re: YellowKey Bitlocker Bypass Vulnerability

#16
post #5

How is this a backdoor if one of the steps is to reboot the system while holding down SHIFT? To boot in the first place, the drive needs to be unlocked.

The EFI partition is unencrypted.

“you don't even need to plug an external storage device, you can just pull out the disk, copy the files in the EFI partition, put it back and it will still work. That's how bad it is.”

Re: YellowKey Bitlocker Bypass Vulnerability

#20
post #12
post #4

Does anyone know if the fix was shipped already? If it not a backdoor, of course.

It does not matter. Who's gonna stop them adding a new backdoor in a later Windows Update(TM) ? T this point they are not to be trusted at all.

Microsoft doesn't need a back door, they can literally sign a new bootchain with the same certificate and install them on your computer.

This is a bug / vulnerability, not a back door.

Post reply on HN