6 ms·
YellowKey Bitlocker Bypass Vulnerability
- coopreme 5mo agoSeems like a backdoor.
- pajko 5mo ago[flagged]
- ranger_danger 5mo agoHow does this prove BitLocker has a backdoor?
- forestry 5mo agoJust because you post about it doesn’t make it so.
- protimewaster 5mo agoWhat's the data in the FsTx folder? Is it just some magic data that Windows looks for?
- e12e 5mo agoLooks like it triggers a debug modus which in turn replay filesystem transactions from transaction logs? https://infosec.exchange/@wdormann/116565129854382214 https://infosec.exchange/@wdormann/116565129854382214
- jllyhill 5mo agoDoes anyone know if the fix was shipped already? If it not a backdoor, of course.
- pajko 5mo agoIt does not matter. Who's gonna stop them adding a new backdoor in a later Windows Update(TM) ? T this point they are not to be trusted at all.
- ChocolateGod 5mo agoMicrosoft doesn't need a back door, they can literally sign a new bootchain with the same certificate and install them on your computer. This is a bug / vulnerability, not a back door.
- majorchord 5mo ago"Who's going to stop <any OS or app> from inserting a backdoor at some random point in the future? They are not to be trusted at all." https://en.wikipedia.org/wiki/Slippery_slope https://en.wikipedia.org/wiki/Slippery_slope
- msuser 5mo agoHow is this a backdoor if one of the steps is to reboot the system while holding down SHIFT? To boot in the first place, the drive needs to be unlocked.
- fh67 5mo agoMost users have it unlocked by TPM only as that is the default Microsoft configuration - you then reboot into windows recovery, yes if windows recovery is disabled or if bitlocker requires a startup pin then this is mitigated.
- msuser 5mo agoPoint taken, but I would call this an authentication bypass (i.e. you can become administrator without any credentials) instead of a BitLocker bypass. It looks like at most, having BitLocker turned on is a requirement to trigger the bug/backdoor. In any case I'd be very curious to read a response to these findings from someone at Microsoft.
- pajko 5mo ago"No, TPM+PIN does not help, the issue is still exploitable regardless, I asked myself this question, can it still work in a TPM+PIN environment ? Yes it does, I'm just not publishing the PoC, I think what's out there is already bad enough." https://deadeclipse666.blogspot.com/2026/05/were-doing-silent-patches-now-huh-also.html https://deadeclipse666.blogspot.com/2026/05/were-doing-silen...
- biennvops 5mo agoInteresting. If TPM+PIN does not help, then what stands between Bitlocker and TPM unsealing the key?
- e12e 5mo agoIn addition to sibling comments, the author claims it also affects tpm+pin.
- anonymars 5mo ago
- rurban 4mo agoJust a little help for the fellow TSA and FBI folks