Earlier quoted context omitted.
> so far as i can tell yellowkey is problematic, as the exploit takes advantage of a backdoor that ms needs, to "manage" your computer. It does look like an intentional backdoor. The way ms is responding to it is even more suspicious. Pretty funny since this defeats security on most corporate laptops, so impact is huge. You'd expect them to treat the reporter better and fix the issue fast... I'm curious why they put…
The backdoor could be a bug, but I don't really understand how it happened. The attack works by having an NTFS log get replayed against another partition than the one the log is stored on. Sending the right signals to unlock Bitlocker in TPM-only mode is a necessity for recovery operations. Managing to replace the executable launched post verification is a plausible attack vector. The weird thing is why it's possible…
Obfuscated enough to pass internal reviews, sloppy enough to make it look like a bug.
Other reply makes it even more suspicious... change is new in a subsystem that hasnt been updated in a long tine and it's only present in recovery mode files.
Microsoft handle of this also screams it's not a regular bug and they're likely investigating or someone is trying to cover their ass.
What's even more troubling is that the fix would be a very simple/quick rollback of the change that introduced this... and that they haven't done that is interesting.