Live data from Hacker News

YellowKey Bitlocker Bypass Vulnerability

github.com

1–10 of 22 posts

Re: YellowKey Bitlocker Bypass Vulnerability

#6
post #5

How is this a backdoor if one of the steps is to reboot the system while holding down SHIFT? To boot in the first place, the drive needs to be unlocked.

Most users have it unlocked by TPM only as that is the default Microsoft configuration - you then reboot into windows recovery, yes if windows recovery is disabled or if bitlocker requires a startup pin then this is mitigated.

Re: YellowKey Bitlocker Bypass Vulnerability

#7
post #6
post #5

How is this a backdoor if one of the steps is to reboot the system while holding down SHIFT? To boot in the first place, the drive needs to be unlocked.

Most users have it unlocked by TPM only as that is the default Microsoft configuration - you then reboot into windows recovery, yes if windows recovery is disabled or if bitlocker requires a startup pin then this is mitigated.

Point taken, but I would call this an authentication bypass (i.e. you can become administrator without any credentials) instead of a BitLocker bypass. It looks like at most, having BitLocker turned on is a requirement to trigger the bug/backdoor.

In any case I'd be very curious to read a response to these findings from someone at Microsoft.

Re: YellowKey Bitlocker Bypass Vulnerability

#10
post #5

How is this a backdoor if one of the steps is to reboot the system while holding down SHIFT? To boot in the first place, the drive needs to be unlocked.

If you have physical access to plug in a flash drive, why would you need the drive unlocked to reboot into the recovery environment? Just power it off and trigger the boot options
Post reply on HN