Live data from Hacker News

Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

techspot.com

151–160 of 280 posts

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#151

Seems this traces back almost a week, from Nightmare-Eclipse who is the researcher who found this: Tuesday, 12 May 2026 - "Here are the links, yes, two vulnerabilities this time [YellowKey] [GreenPlasma] [...] Next patch tuesday will have a big surprise for you Microsoft" Wednesday, 13 May 2026 - "I can't wait when I will be allowed to disclose the full story, I think people will find my crashout very reasonable and…

Previously discussed numerous times on HN, like: https://news.ycombinator.com/item?id=48130519

Whether this is a backdoor or not boils down to whatever your usual proclivities about "bug or backdoor" are; it's not like "if microsoft = 1 hack bitlocker" like the tech press seem to love to report.

This is a bug in the NTFS transaction log replay functionality in the Windows Recovery Environment WinRE, where it will read NTFS transaction logs from an external volume and apply them to the mounted filesystem. This allows the attacker to perform an authentication bypass against WinRE. With BitLocker without PIN or Password, _any_ authentication bypass becomes a disk encryption bypass, since the disk is unsealed by the bootloader (this architectural "flaw" is true for Linux with the same configuration, as well, like Ubuntu installed with their newish Hardware Disk Encryption checkbox in the installer).

In lieu of additional evidence, whether you think the NTFS transaction log issue is a planted backdoor or a simple enumeration bug depends on your conspiracy theory level, like most things in exploit development. To me, it seems like a plausible bug. The weaknesses in boot-time unseal are well known and obvious and this is just one of many, so I don't see it as an earth-shattering revelation, although it is a fun bug.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#152

Earlier quoted context omitted.

[flagged]

even Bill Gates bailed out of M$ https://finbold.com/bill-gates-foundation-fully-dumps-its-mi...

He personally still owns 100m shares (per your article) and has not bailed out.

The B&MG foundation sold their remaining 7.7m shares.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#153

I just digged into the exploit a little bit more and what it does it targets BitLocker in TPM only mode. That means that there is no preboot authentication or anything. What happens is secure boot validates the boot chain and the TPM gives out the encryption keys by itself. When you have physical access, it doesn't really make a difference. If there is a stick you can boot from and drop into an emergency shell or if…

> What Microsoft is doing here in general they are selling something that is not secure. They are selling it as as full disk encryption but it's not.

But you can configure Linux LUKS in the exact same way.

This doesn't seem an attack on BitLocker so much as it is an attack on the secure boot chain.

The value of PIN-less unlock is if your threat model is limited to the disk being disposed of or removed from the machine or otherwise separated from the TPM.

Entering a PIN is inconvenient or impossible if more than one user regularly uses the device. Hence, control to validate access is transferred to a trusted OS component.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#154
post #94

From: https://infosec.exchange/@wdormann/116565129854382214 >In a normal WinRE session, you have a X:\Windows\System32 directory that has a winpeshl.ini file in it >However, with the YellowKey exploit, it looks like Transactional NTFS bits on a USB Drive are able to delete the winpeshl.ini file on ANOTHER DRIVE Interesting. I dont know about this environment - some kind of naive file handle contructing/passing? But t…

>The thousands of winre thumb drives are certainly out of reach; maybe the bitlocker side update the access permissions? Would it require unenc/reenc? The part that isn't mentioned is that the win re is privileged because windows stores a decryption key in the TPM that allows win re to decrypt the disk even without the recovery key. That's why the attack requires win re in the first place, rather than booting into an…

> This also means you don't have to patch all the winRE thumbdrives out there because their secureboot signatures can simply be revoked, meaning they can't pass TPM validation anymore, therefore they won't be able to decrypt any disks.

WinRE runs internally, not from a thumb drive, which is why the bootloader will unseal the disk for it (just like if you have a systemd recovery set up on a Linux distribution). It doesn't have a separate key or anything, it's just allowed to use the "main" one, by design. Microsoft just need to patch the WinRE partition in a normal Windows Update to fix the NTFS transaction log driver; no Secure Boot revocation or TPM-related changes are necessary (which is good for them, because _that_ would be a disaster).

By and large this whole thing is orthogonal to BitLocker overall; boot-time unsealed BitLocker is vulnerable to any post-bootloader auth bypass by design, and this is a goofy post-bootloader auth bypass bug.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#155
Seems bullshit, apparently it only works with TPM-only mode, which is obviously insecure (it relies on neither the OS nor the hardware being exploitable, on a random Windows PC...), and not worth building a backdoor for.

The way one would backdoor something like Bitlocker is to encrypt the disk encryption key with a (post-quantum) public key for which only the backdoor owner has the private key for, and then put it on a place on disk that is unused by the filesystem.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#157
post #75
post #68

Earlier quoted context omitted.

Presumably, not paying out for these bugs which often take weeks of research to find.

Who in their right mind bets on bug bounties to cover their basic needs? They should be highly employable with these kind of skills.

If you take the statement at face value, that does not appear to be the case. If you don’t take it at face value, the underlying presumptions might be a lot of why they may not be employable.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#158
post #144
post #131

Earlier quoted context omitted.

Really depends on your background doesn't it? You could have convictions, be sanctioned, have visa problems, or all kinds of things that are not easily solvable.

To say nothing of mental health issues.

Or poverty. Or addiction.

Or that entire holy trinity.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#159

Earlier quoted context omitted.

Fiasco? You mean where they voluntarily shut down rather than compromise themselves? Or are you referring to another matter?

Presumably when the authors of TrueCrypt declared “Using TrueCrypt is not secure” If I trust them to provide my FDE software, I certainly trust them when they say I shouldn’t use it.

My interpretation was that the authors received a National Security Letter and chose to shut down development rather than let their software get backdoored. IIRC the shutdown announcement cited the discontinuation of Windows XP as why the software got discontinued (when it was cross platform and supported newer versions of Windows) and included a step-by-step guide for how to migrate to Bitlocker (a red flag for anyone remotely cynical).

An independent audit of the last version of TrueCrypt was published about a year after the discontinuation. It did not find any significant security issues or backdoors.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#160
post #11

At what point will Security professionals start turning down roles that involve “securing” MS Products? I’m already at this point. Securing Microsoft products is busy work while waiting to have it undercut by the next wave of MS’s insane tech debt and greed. And now backdoors!

> And now backdoors! "now"? Shall we have a discussion about the excuse Microsoft gave as to why keys they claimed, back then, were "secondary keys" belonging to Microsoft, were called ..._NSAKEY when a version of Windows NT shipped, by mistake, with debug symbols on? One time, just freaking one time, a version of Windows shipped with debug symbols on and, by chance, there had to be cryptographic keys named "NSAKEY"…

The bit I never understood in this story is the accidental leak of the debug symbols. Microsoft publishes them anyway. They are not a secret. Back in the day, the symbols shipped on the CD, and they published updated symbol packages for service packs. Nowadays they are published on the web and their debuggers download the symbols automatically.
Post reply on HN