Live data from Hacker News

Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

techspot.com

21–30 of 280 posts

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#21
post #14

Earlier quoted context omitted.

My harddrives (laptop, work laptop, desktop, server) contain emails, browser sessions, saved passwords, personal data from family and friends. I do not want someone stealing my laptop on a train ride potentially being able to have all of that data. With a proper real backup strategy, i have everything save. I do not need easy access to a hard drive from a broken computer. But hey you do you :)

Are you saying you bring your desktop on a train ride as well? Laptops with encryption make sense; if you need to encrypt your desktop, I have questions.

Simple hypothetical: "A disaster hits and the workstation owner is unable to return to the location the workstation is stored. During that time period the workstation is stolen by a gang of looters."

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#22

Earlier quoted context omitted.

You only need to use the aka.ms link if you lost your recovery key. That feature also can be disabled without disabling Bitlocker as a whole.

How would a user that never set it up in the first place have a recovery key? I honestly am asking and don't know. I recently (last week) had to drive over to a parent's house and "fix" their (pre-online accounts) win 11 computer used for sewing because it had become a blue screen saying aka.ms was required. They did not know how it happened and are not very technical users so I imagine they were tricked by some clic…

The non-cloud methods for recovering the key have been the same since Bitlocker was released 19 years ago.

https://support.microsoft.com/en-us/windows/find-your-bitloc...

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#23

Title sounds conspiratorial, but it lines up well with the controversy around TrueCrypt's discontinuation which, I believe, specifically called out BitLocker as an alternative to use in future.

That was my immediate first thought. "Oh, is Bitlocker Not Safe Anymore?"

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#24
post #11

At what point will Security professionals start turning down roles that involve “securing” MS Products? I’m already at this point. Securing Microsoft products is busy work while waiting to have it undercut by the next wave of MS’s insane tech debt and greed. And now backdoors!

As opposed to iOS, which does iCloud backups that are not E2E encrypted by default, so that law enforcement can request your chats (except Signal because they opt out), browser history, etc.? You can enable ADP for E2E encrypted backups, but it's probable not going to help you much, because the people you are communicating with likely didn't. This is not to defend Microsoft, more to say that all these companies were…

> This is not to defend Microsoft

But you are defending MS, conflating a bunch of things, mainly full disk encryption and cloud backups.

There's a big difference between Apples cloud backup which has documented behavior and a backdoor. I'm also fairly confidant in Apple's full disk encryption, they've gone to court to defend it. There also a lot more data points we can use to judge Apple vs Microsoft on privacy and security, and MS comes out looking bad.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#25
post #17
post #13

Earlier quoted context omitted.

Cool. Everyone's threat model is different. As long as we're not writing passwords on sticky notes attached to the monitor, I don't think there's any need to be throwing stones.

Hey now, I use rot13 on my sticky notes.

Gotta bump that encryption up - rot26 is twice as secure.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#26

Title sounds conspiratorial, but it lines up well with the controversy around TrueCrypt's discontinuation which, I believe, specifically called out BitLocker as an alternative to use in future.

I'm not aware of the connection between truecrypt and bitlocker, want to enlighten us?

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#27

Earlier quoted context omitted.

How would a user that never set it up in the first place have a recovery key? I honestly am asking and don't know. I recently (last week) had to drive over to a parent's house and "fix" their (pre-online accounts) win 11 computer used for sewing because it had become a blue screen saying aka.ms was required. They did not know how it happened and are not very technical users so I imagine they were tricked by some clic…

The non-cloud methods for recovering the key have been the same since Bitlocker was released 19 years ago. https://support.microsoft.com/en-us/windows/find-your-bitloc...

I think there's been some miscommunication. If the bitlocker activation happens during tricking the user into going from a local account to online account, it is without the user's consent or real participation. They haven't printed out a copy of the key or moved it to a usb drive. They aren't aware their drives are being encrypted. They can't set up recovery keys now because the computer itself only shows the blue aka.ms screen. None of those 2/4 options are applicable.

There other 2 options are enterprise or online account (the very thing we're talking about) don't apply in this context.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#29
post #2

As long as Microsoft will continue to use dark patterns to convert local accounts to online accounts and automatically, without user consent, encrypt the storage drives preventing any computer use until the user goes to aka.ms and through the hoops, this is a good thing. No one should have their data encrypted and kept from them without consent unless they do something. Microsoft does that now. They may not be requri…

The nagging to upgrade is insane. Even the 'dismissal' option is a dark pattern still designed to make you click the wrong thing

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#30

Seems this traces back almost a week, from Nightmare-Eclipse who is the researcher who found this: Tuesday, 12 May 2026 - "Here are the links, yes, two vulnerabilities this time [YellowKey] [GreenPlasma] [...] Next patch tuesday will have a big surprise for you Microsoft" Wednesday, 13 May 2026 - "I can't wait when I will be allowed to disclose the full story, I think people will find my crashout very reasonable and…

I read it as the author is / was going through the vulnerability disclosure process with Microsoft and they're annoyed for unclear reasons and decided to publicly disclose, rather than being an insider.
Post reply on HN