6 ms·
Microsoft BitLocker – YellowKey zero-day exploit
- ungreased0675 5mo agoRemarkable. Does MS take a huge reputational hit for having a backdoor, or are they so essential to most places this won’t matter?
- peroids 5mo agoI’m assuming the EU speeds up the uncoupling cause of some of this.
- ranger_danger 5mo agoAs far as I can tell, there's no concrete evidence that it is actually an intentional "backdoor."
- skeptic_ai 5mo ago[flagged]
- majorchord 5mo ago> lol it's an obvious backdoor in your opinion
- 3eb7988a1663 5mo agoWhat would you require to feel confident it is a backdoor? Nadella gives a press release, "Alright guys, you got us fair and square. Backdoor on Bootlocker. Various versions of it for years on behalf of the spooks." You are unlikely to ever get a confirmation of wrong doing. That being said, for a first line security posture, there is no way external media should have anything to do with the encryption process. Even if the OS chose to read a USB drive, to also delete the magical files is ridiculously suspect. It could always be plain old incompetence, but that is a damning level of technical ineptitude assigned to such critical infrastructure. This is not a project you assign to the intern, but paranoid security experts. Multiple levels of code review and red-teaming.
- Dylan16807 5mo ago> there is no way external media should have anything to do with the encryption process. Does this exploit have external media having anything to do with the encryption process? If yes, how do we know that? Remember that the OS normally unlocks the drive on boot, when no exploits are happening. > Even if the OS chose to read a USB drive, to also delete the magical files is ridiculously suspect. It's files in System Volume Information describing a transaction or something. It makes sense for it to resolve that transaction when mounting the external drive, and to then delete the files. And that's if it's even windows itself triggering the deletion.
- charcircuit 5mo agoIt's not an actual backdoor. An attacker found a way to exploit Windows after booting it up in this recovery mode. The security of files on the device depends on it being impossible for Windows to be pwned by an attacker on any surface exposed before the user is unlocked. This is why operating systems like GrapheneOS disable the USB port on the initial boot to limit the attack surface that an attacker has.
- tsimionescu 5mo agoHaving a specific file name trigger the decryption to happen automatically, while also removing said files after this is achieved, is an extremely unlikely bug. I think for most people evaluating this, the onus is now on anyone thinking this is not a backdoor to prove how a mistake in the code can trigger this very specific scenario. This is like finding out that an OS accepts an SSH private key circulating online that the sysadmin for those OS boxes never authorized, and saying "wait, we don't know that this is a backdoor into that system, the attackers just found a bug".
- charcircuit 5mo ago>Having a specific file name trigger the decryption That is not what happens. There is nothing wrong with decrypting the drive. If you just powered on the computer normally, it will "trigger the decryption." There just isn't way to read a file from the lock screen. This exploit is getting you to a state where the drive is unlocked but the user has access to a command prompt. A command prompt, unlike a basic login screen gives the user the ability to actually see the contents of arbitrary files. >specific file name It's a specific file name because Windows stores transaction logs under that name. If it was a random name it wouldn't be able to exercise this vulnerable code. >also removing said files after this is achieved It doesn't seem farfetched for a transaction log to be deleted after it is successfully replayed.
- solenoid0937 5mo agoThis is 1000% a backdoor if you understand how the BitLocker process works.
- avazhi 5mo agoI think anybody who has been paying attention has assumed for at least 20 years that all of Microsoft’s shit is backdoored anyway. I mean, the original Snowden revelations made that abundantly clear if it wasn’t before then. Businesses use Microsoft because they figure if it’s backdoored it doesn’t matter and won’t affect them (because they aren’t terrorists or child pornographers or whatever, and they’d comply with a subpoena regardless of if Bitlocker is backdoored or not) and individuals who care about security and privacy put their shit on a Veracrypt drive somewhere else.
- anal_reactor 5mo agoI guess that most people who use security features of Microsoft products only do so to tick compliance checkboxes and they really don't give a fuck about actual security. Which makes me think, it's becoming more and more urgent to make an open source mobile OS happen.
- AndroTux 5mo agoI don’t think anyone is using Windows for privacy, so I’d say nobody will care.
- danpalmer 5mo agoBut almost every business is using Windows and depending on its security.
- mystifyingpoi 5mo agoBusiness side is different. I have a company provided Windows laptop and I could not care less about it's privacy or security - it's my employer problem, or at most my employer's IT/secops department. But Windows for personal private use? No.
- realusername 5mo agoNothing has changed since the old days, Windows still isn't appropriate for sensitive or secure operations. (I'm aware that there's going to be a significant gap between the theory and what happens in practice though)
- deleted 5mo ago[deleted]
- esseph 5mo agoIt's used at every bank, every government institution, even carriers and nuclear submarines.
- AnonC 5mo agoThe BitLocker exploit seems simple and very dangerous. Companies and individuals have been relying on BitLocker to protect information if the device is lost. Despite promises, Microsoft doesn’t seem to be serious about security. What will it take for more companies to truly understand their risks with Windows and being locked into Microsoft’s platforms?
- ranger_danger 5mo agoHow does a bug equate to "not serious about security"?
- navigate8310 5mo agoThere's no way this is not a backdoor
- thewebguyd 5mo agoGiven that the other two vulns were silently patched, no CVE, basically screams this is a backdoor. If this is a fed mandated backdoor, I guarantee Microsoft/Windows isn't the only one either, they are just the only/first ones to get caught. I'd be suspicious about every single commercial, closed source operating system or encryption product in the US right now.
- Our_Benefactors 5mo ago[flagged]
- forestry 5mo ago*in your opinion.
- Our_Benefactors 5mo agoThis is a bad faith comment. Both positions are an opinion.
- otterley 5mo agoHere's the primary source: https://deadeclipse666.blogspot.com/2026/05/two-more-public-disclosures-it-will.html https://deadeclipse666.blogspot.com/2026/05/two-more-public-... Other links: https://github.com/Nightmare-Eclipse/YellowKey https://github.com/Nightmare-Eclipse/YellowKey https://github.com/Nightmare-Eclipse/GreenPlasma https://github.com/Nightmare-Eclipse/GreenPlasma
- pajko 5mo agoEarlier thread: https://news.ycombinator.com/item?id=48114997 https://news.ycombinator.com/item?id=48114997
- bombcar 5mo agoHow is this even possible, backdoor or no? Isn't the whole point of this type of encryption that even a compromised machine can't decrypt without the passphrase? If this works it means that the key is stored unencrypted somewhere?
- andrecarini 5mo agoPresumably the key is stored in the TPM
- majorchord 5mo agoMost setups only have the key stored in the TPM, so all you need to get it back is a signed/trusted bootloader. Ideally you'd want that key to be further protected with a password or some other mechanism because it's not impossible to extract TPM keys.
- ranger_danger 5mo agoFor those who use password (not PIN) based pre-boot authentication with BitLocker... do we know if that setup is safe? I can't imagine there would be a way to bypass that if a password is required, unless it was a situation where like, there was originally some secret secondary key made that needs no password... or the password was never tied to the key in the first place.
- andrecarini 5mo agoThe exploit developer themselves say [1] TPM+PIN is vulnerable, though no public PoC. [1]: https://deadeclipse666.blogspot.com/2026/05/were-doing-silent-patches-now-huh-also.html?m=1 https://deadeclipse666.blogspot.com/2026/05/were-doing-silen...
- forestry 5mo agoI’m skeptical of that claim. The key material presumably is inaccessible even to the OS without the passcode.
- ranger_danger 5mo ago> presumably That's the thing, we don't actually know how involved the PIN is in relation to the key... it might be completely separate (and hence bypassable). Similarly I also wonder if password-based pre-boot auth is affected.
- redprince 5mo agoThat is known pretty well: The TPM won't release the the volume key unless the correct PIN is presented to the TPM.
- ranger_danger 5mo agoThe only evidence I have seen was this article that another user in the thread shared: https://blog.scrt.ch/2024/10/28/privilege-escalation-through-tpm-sniffing-when-bitlocker-pin-is-enabled/ https://blog.scrt.ch/2024/10/28/privilege-escalation-through... Not saying you're wrong, I'm just not sure how well known it really is. Either way... if the TPM is the one gating the key behind a PIN, I really don't see how an OS-level exploit can work without knowing the PIN in advance.
- Nition 5mo agoThis looking so much like an intentional backdoor just makes me wonder even more about TrueCrypt's sudden recommendation in 2014 that everyone switch to BitLocker. This particular backdoor didn't exist then (it's only Win11 apparently) but this sure makes it seem more plausible that another one might have. Though if TrueCrypt was killed to try and get people to switch to encryption that could be backdoored, then why allow its successor VeraCrypt to exist? It's open source and independently audited, so it really shouldn't be backdoored.
- misone 5mo agohttps://infosec.exchange/@wdormann/116565129854382214 https://infosec.exchange/@wdormann/116565129854382214
- DANmode 5mo ago> Mitigation: Use Bitlocker with a PIN. > (Note: The YellowKey author disagrees that PIN is a protection
- jackjeff 5mo agoThat’s the most puzzling part to me. What’s the point of the PIN then? I was assuming it was mixed with the TPM secret somehow but if it can be bypassed then it shows it just an IF statement somewhere. Dang… God I hate this stupid design of burying the decryption key in the TPM and hoping the software does not get fooled to reveal it. Microsoft always sucks. Why don’t you ask for the password at boot time and derive the key from it. So much simpler and makes this kind of attacks impossible. Nobody is going to bypass LUKS or FileVault like this.
- solenoid0937 5mo agoThe amount of trust put into buggy TPM implementations chock full of vulnerabilities has always confused me. Does anyone really trust these shitty Windows laptop/desktop manufacturers to get these things right? These guys couldn't even get basic hardware features like trackpad drivers right.
- ChrisArchitect 5mo ago[dupe] https://news.ycombinator.com/item?id=48129789 https://news.ycombinator.com/item?id=48129789 And earlier https://news.ycombinator.com/item?id=48114997 https://news.ycombinator.com/item?id=48114997
- iscoelho 5mo agoWhat's with all the replies on these threads downplaying this? Why is it mainly brand new accounts? What's going on here? I've seen every variant of: 1) "this is an authentication/privilege escalation bug, not a bitlocker exploit" (? what are you even trying to say) 2) "even though the attacker explicitly warns that this is capable of bypassing TPM+PIN, that isn't actually true or what he meant" 3) "we shouldn't jump to conclusions that this is a backdoor" 4) "we already knew BitLocker with just TPM isn't secure" (? except many organizations depend on it to be)
- gib444 5mo agoMost submissions involving criticism of big tech gets those kind of replies. Par for the course here. You just have to skip reading them because it seems there's no stopping those 100% genuine replies
- deleted 5mo ago[deleted]
- Dylan16807 5mo ago1) These systems are set up for automatic decryption. It's super obvious that if you can successfully attack windows between unlock and user login, you can get to the files. If this is such an attack, it's not a flaw with bitlocker itself. 2) Is it unreasonable to say "show it"? 3) Correct, we shouldn't jump to conclusions. 4) It's not known-insecure but it is known-enormous-attack-surface.
- iscoelho 5mo ago1) Except that the entire premise behind BitLocker TPM's security relies on the login screen as a hard security boundary, and thus any attack on the login screen is an attack on BitLocker. It is semantics to dispute this and certainly fits "downplaying." 2) I'm sure many organizations are thankful that the researcher has decided not to release that exploit chain at this time. I am hopeful that Microsoft will not be as dismissive and will resolve it before it is publicly released. 3) It distracts from the point. The point is that Microsoft's security record is so bad that many of the vulnerabilities appear deliberate and obvious enough to be backdoors. 4) Yes, this also fits the definition of downplaying.
- himata4113 5mo agobitlocker is generally useless unless the hardware is secure to begin with and while we have tons of 'boot guard' implementations which fuse the certificate into hardware meaning that only the OEM can create firmware that will boot there have been at least 2 instances of these certificates leaking exposing all hardware with that signature and other bypass methods (some boot guards are 'flash' guards were you can only flash signed firmware, but doesn't stop you from directly flashing the spi bios chip). I had someone demo me preserving PCR values by patching SMM module in firmware without triggering any bitlocker lockout, this also means that you can externally write bios with the smm module as long as you have ~2 minutes to disassemble the laptop or desktop and flash firmware. This hurts the most when you don't have PIN authentication which means you just need to steal the laptop to exfiltrate data, if you do then you have to have the user boot which then drops a payload exfiltrating data over network or just stealing the laptop again as you can write back decryption keys into non encrypted partition or corrupt some sectors at the end of the disk and write them there. * modifying smm allows you to patch the boot process loading a malicious payload into hypervisor/kernel.
- HackerThemAll 5mo ago> unless the hardware is secure to begin Majority of hard disk encryption done in the HDD/SSD controller is 100 times more crap than BitLocker itself. It's littered with bugs and security vulns. Anybody using it is insane.
- himata4113 5mo agowe're not talking about the hdd/ssd here, those are not really encryption but data packing and compression algorithms, they added encryption because it's a single instruction for extra talking points. you use veracrypt which doesn't have any hardware attestation (convenience) features, but it does still leave you vulnerable to the same surface PIN+TPM is vulnerable to. the real defense is making it so opening your laptop/desktop physically fuses something via latch and wipes the key off your system requiring re-entry. of course, who wants to own a laptop/desktop that you can't open we have enough of that with our phones.
- 5mo ago
- stackghost 5mo agoWhat's with these two new accounts, `aiscoming` and `forestry`, being weirdly aggressive in their defense of bitlocker?
- aiscoming 5mo agoI get paid to defend AI and MSFT online. quite lucrative business. DM me if you are interested
- ReptileMan 5mo agoSo is bitlocker not using TPM vulnerable? Bitlocker at rest? It is not really clear.
- lostmsu 5mo agoThis is an attack on boot process. If Windows does not decrypt your volume automatically on boot, it does not work.
- anonymars 5mo agoMaybe, maybe not https://deadeclipse666.blogspot.com/2026/05/were-doing-silent-patches-now-huh-also.html?m=1#:~:text=Second%20thing%20is%2C%20No%2C%20TPM%2BPIN%20does%20not%20help%2C%20the%20issue%20is%20still%20exploitable%20regardless%2C%20I%20asked%20myself%20this%20question%2C%20can%20it%20still%20work%20in%20a%20TPM%2BPIN%20environment%20%3F%20Yes%20it%20does%2C%20I%27m%20just%20not%20publishing%20the%20PoC%2C%20I%20think%20what%27s%20out%20there%20is%20already%20bad%20enough. https://deadeclipse666.blogspot.com/2026/05/were-doing-silen...
- felooboolooomba 5mo agoWhen I see a bug that walks like a backdoor and swims like a backdoor and quacks like a backdoor I call that bug a backdoor.
- lofaszvanitt 5mo ago.
- red_admiral 5mo agoProperly secure symmetric encryption needs a key with at least 128 bits of entropy. In the "device lost/stolen" scenario, that key must not be on the device. Key inside a TPM on the device itself is DRM, nothing more. There's better and worse DRM, I think the iPhone bootloader one is one of the better ones, but it's still just DRM. You either need to enter a 128-bit entropy password on every boot (good luck with that) or you need to hold it on some external device, with some variant of USB / smartcard / NFC / Bluetooth to transmit it. NB. this is one of the cases where the usual "key for signing only, never leaves device, ephemeral DH and ZK protocols" like for SSH will not work on its own; you need the high-entropy key physically separate from the device. The NSA realised this a while ago: https://en.wikipedia.org/wiki/KSD-64 https://en.wikipedia.org/wiki/KSD-64 Linux/LUKS etc. doesn't change any of this, by the way. P.S. If Eclipse really has beef with Microsoft, he could always make an exploit that lets you set up a PC without making a Microsoft account.
- perching_aix 5mo agoSo much this. Security information should simply never reside on-device in the first place. That said, I think this is a thing with BitLocker? I remember coming across YubiKeys being able to do this via something called PIV (Personal Identity Verification). Found this guide now after giving it a quick search: https://gist.github.com/daemonhorn/03301a66da7d1f4de6cdc8c8bbd171da https://gist.github.com/daemonhorn/03301a66da7d1f4de6cdc8c8b... Not sure how sound of a design it is though, didn't dig into it much at all.
- Borealid 5mo agoWith PIV, the private keys are stored inside the smartcard (a Yubikey is just one type of smartcard) and don't leave it. They're used for encryption/decryption by the host. Yes, it's generally sound, and is the primary means of authentication and encryption used by the US military for classified systems.
- kristjank 5mo agoLinux+LUKS enables FIDO2, which uses sha256, meets the requirements of "never leaves the device" and keeps it on a separate device, on a separate secure element.
- rustyhancock 5mo agoCrikey, it seems that the big news - a backdoor is somewhat burried. It also strikes me that these are several very high value (all but one complete) exploits. Surely the value of these on the market would be astronomical and best suited to law enforcement agencies using unlock as a service businesses. So I have to say I applaud the open disclosure
- mylastattempt 5mo agoThough I am convinced this is intentional, i.e. a backdoor and not a bug, it should be noted that for goverment agencies there was already access anyway: https://news.ycombinator.com/item?id=46735545 https://news.ycombinator.com/item?id=46735545
- mananaysiempre 5mo agoAccess for those who used a Microsoft account and upload their encryption keys there. While I’m unhappy that most of the users end up using this (bad) mode, previously I was under the impression that there was a meaningful choice involved.
- rustyhancock 5mo agoYes it does seem prudent to encrypt those keys some other way on the cloud and not add them to the clouds accessible keys. They also seem suitable for using a secret sharing scheme. I have Microsoft authenticator requests all day every day. Using aliases has helped but somehow they continue. It's only a matter of time before somehow accidentally I approve. Which has simply led to me not putting anything of high value in my Microsoft account and not using it for my email.
- willis936 5mo agoThis happened to me too. The only solution I found was to disable authenticator on the account. Their implementation actively makes accounts less secure.
- 5mo ago
- GTP 5mo agoMy only doubt about YellowKey is, does it require having access to an already unlocked machine (i.e., the user is logged in) to copy the required files?
- Borealid 5mo agoIt does not. The files are copied to the recovery image, not the machine's encrypted drives.
- GTP 5mo agoMy concern isn't where they are copied to, but where they are copied from.
- Borealid 5mo agoThey are copied from a thumb drive the person applying the exploit creates.
- GTP 4mo agoYes, but my question was where the files on the thumb drive are coming from. At first, my understanding was that you needed to get them from the victim's machine. But, after watching a LowLevel video on YouTube, it seems those are universal files that you can get from the exploit's repo.
- LelouBil 5mo agoI saw someone on Reddit ask if it would be possible to write a known vulnerable WinRE version on the drive (or another drive ?) if this got patched? I do not know bitlocker/TPMs a lot, do they also prevent this sort of thing ?
- luke-stanley 5mo agoI'm not sure that copying a key after unlocking the system counts as a backdoor? If the OS promises to lock access to the key and fails to do so then I can see the logic that people might then call that a backdoor. But it's different from there being a key bypass, or a pre-shared key (or such), which it seems like the article suggests? For the record, I don't use Windows (so glad).
- bri3d 5mo agoRight, this is a Windows auth bypass that works with Bitlocker enabled; using TPM-only Bitlocker you are vulnerable to _any_ postboot authentication bypass or memory content extraction technique, this is just a particularly stupid / weird auth bypass technique that has been spun really hard by the author and press. For what it's worth, any OS using only hardware identity to unseal disk encryption is vulnerable to the same class of attack; there are all sorts of ways to misconfigure or exploit Linux FDE setups to enter a recovery shell as well. It's still a huge step above "no disk protection" (especially since it protects against every scenario where the disk is separated from the hardware), but the postboot surface area is enormous and nobody should be considering this class of protection as much more than a speed bump for a serious attacker.
- atesti 5mo agoDoes anybody know what FsTx actually is? Is there any documentation about it?
- fortran77 5mo agoOn my newest laptop, an Asus Zenbook A16, the BIOS (a Insyde 309 3.08) has NO way to disable USB boot or even to change the boot priority. I enabled a BIOS password, secure boot, and a Bitlocker PIN (so my computer boots into a special boot screen before Bitlocker is unlocked) but I'm still not sure if this is enough.