Live data from Hacker News

Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

techspot.com

161–170 of 280 posts

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#161
post #54

Earlier quoted context omitted.

I read it as the author is / was going through the vulnerability disclosure process with Microsoft and they're annoyed for unclear reasons and decided to publicly disclose, rather than being an insider.

How would that leave them homeless?

Many brilliant people have serious mental health issues that preclude their ability to regulate their emotions and act maturely in serious situations e.g. responsible vulnerability disclosure.

I've watched genius-level IQ people get fired time and again because they don't know how to work with others at a basic kindergarten level.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#162
post #11

At what point will Security professionals start turning down roles that involve “securing” MS Products? I’m already at this point. Securing Microsoft products is busy work while waiting to have it undercut by the next wave of MS’s insane tech debt and greed. And now backdoors!

> And now backdoors! "now"? Shall we have a discussion about the excuse Microsoft gave as to why keys they claimed, back then, were "secondary keys" belonging to Microsoft, were called ..._NSAKEY when a version of Windows NT shipped, by mistake, with debug symbols on? One time, just freaking one time, a version of Windows shipped with debug symbols on and, by chance, there had to be cryptographic keys named "NSAKEY"…

Had to look this up myself.

https://en.wikipedia.org/wiki/NSAKEY

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#163
post #132

Earlier quoted context omitted.

Please let me know when finding a job in software engineering in 2026 is feasible for everyone with ‘computer skills’.

The guy doesn’t just have „computer skills“ if he found this.

Good luck convincing a HR automaton not looking at your resume for the job unposting of that.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#164
post #104
post #96

Earlier quoted context omitted.

people with values different from yours, presumably

This is one it those answers that seems on the surface like it contains insight but on closer inspection it’s vacuous. This could be rewritten as “because they aren’t you”, which is true but not a meaningful or educational answer.

This entire thread is generally weird.

If someone has this kind of exploit and can't get a bug bounty for it, and desperately needs the money, he can sell it for 100k+ in a shady black market

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#165
post #88

Better writeup: https://infosec.exchange/@wdormann/116565129854382214 The published exploit doesn’t affect Bitlocker with a PIN, without which Bitlocker isn’t secure anyway. The original author claims they have an exploit that also works with a PIN, but hasn’t provided any proof of that.

[deleted]

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#166

Earlier quoted context omitted.

The guy doesn’t just have „computer skills“ if he found this.

Good luck convincing a HR automaton not looking at your resume for the job unposting of that.

Come on, with these skills you could convince someone to give you a job if you’re on the streets otherwise. You might not be a senior engineer in the exact thing you want but you won’t be on the streets.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#167
post #151

Seems this traces back almost a week, from Nightmare-Eclipse who is the researcher who found this: Tuesday, 12 May 2026 - "Here are the links, yes, two vulnerabilities this time [YellowKey] [GreenPlasma] [...] Next patch tuesday will have a big surprise for you Microsoft" Wednesday, 13 May 2026 - "I can't wait when I will be allowed to disclose the full story, I think people will find my crashout very reasonable and…

Previously discussed numerous times on HN, like: https://news.ycombinator.com/item?id=48130519 Whether this is a backdoor or not boils down to whatever your usual proclivities about "bug or backdoor" are; it's not like "if microsoft = 1 hack bitlocker" like the tech press seem to love to report. This is a bug in the NTFS transaction log replay functionality in the Windows Recovery Environment WinRE, where it will rea…

It's very strange that the same component exists in Windows without the issue, though. Like the author, I'm finding it difficult to come up with reasons why they'd be different.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#168

Earlier quoted context omitted.

Curious to see this take from you! I followed TrueCrypt for years, but always thought it was very strange that they were anonymous, and then the mysterious shutdown happened, and I have no idea what to make of VeraCrypt. It's been in my "possibly good, but too many weird flags around the whole project" bucket. Anything in particular that makes you wary? I'm aware of the 2016 and 2020 audits ( https://ostif.org/the-ve…

this crypto solution got their driver licence pulled afaik they cant update their program anymore / get new drivers loaded properly

[dead]

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#169
post #36
post #32

"Security professionals generally recommend avoiding reliance on any single encryption system and instead evaluating well-reviewed full-disk encryption alternatives such as VeraCrypt". If they put a backdoor into FDE it would make more sense to advise people to stop using windows at all and using Linux instead. If they put a backdoor in FDE you can be sure there is not just one backdoor in the operating system itself…

I don't use Microsoft products generally but not with even with your computer would I run VeraCrypt.

[citation needed]

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#170
post #36

Earlier quoted context omitted.

I don't use Microsoft products generally but not with even with your computer would I run VeraCrypt.

[citation needed]

Ok. You got me. I would run VeraCrypt on your computer. The one exception.
Post reply on HN