16 ms·
Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
- superkuh 5mo agoAs long as Microsoft will continue to use dark patterns to convert local accounts to online accounts and automatically, without user consent, encrypt the storage drives preventing any computer use until the user goes to aka.ms and through the hoops, this is a good thing. No one should have their data encrypted and kept from them without consent unless they do something. Microsoft does that now. They may not be requring a monetary ransom like others, but it is a ransom nevertheless. I know this is controversial. Bitlocker helps protect one's property and information when used intentionally. And that being impacted is a shame.
- mynameisvlad 5mo agoYou only need to use the aka.ms link if you lost your recovery key. That feature also can be disabled without disabling Bitlocker as a whole.
- superkuh 5mo agoHow would a user that never set it up in the first place have a recovery key? I honestly am asking and don't know. I recently (last week) had to drive over to a parent's house and "fix" their (pre-online accounts) win 11 computer used for sewing because it had become a blue screen saying aka.ms was required. They did not know how it happened and are not very technical users so I imagine they were tricked by some click-through dialog. It is not something they would ever do intentionally. All that computer ever does is run sewing pattern/control software.
- mynameisvlad 5mo agoThe non-cloud methods for recovering the key have been the same since Bitlocker was released 19 years ago. https://support.microsoft.com/en-us/windows/find-your-bitlocker-recovery-key-6b71ad27-0b89-ea08-f143-056f5ab347d6 https://support.microsoft.com/en-us/windows/find-your-bitloc...
- superkuh 5mo agoI think there's been some miscommunication. If the bitlocker activation happens during tricking the user into going from a local account to online account, it is without the user's consent or real participation. They haven't printed out a copy of the key or moved it to a usb drive. They aren't aware their drives are being encrypted. They can't set up recovery keys now because the computer itself only shows the blue aka.ms screen. None of those 2/4 options are applicable. There other 2 options are enterprise or online account (the very thing we're talking about) don't apply in this context.
- mynameisvlad 5mo agoYou can set up recovery keys at any point in time, not just at creation. Just because people don't do it doesn't mean it isn't and hasn't been available for almost 2 decades.
- Silhouette 5mo agoAnd presumably the instructions for this have been on display on our local planning department in Alpha Centauri? If a user isn't even aware that their local disk is being encrypted without their knowledge or consent then why would they think to set up recovery keys?
- whycome 5mo agoThe nagging to upgrade is insane. Even the 'dismissal' option is a dark pattern still designed to make you click the wrong thing
- deleted 5mo ago[deleted]
- archerx 5mo agoMaybe I’m an outlier but I don’t want my drives encrypted at all. I rather have all my data be accessible if things go catastrophic, I.E. having to pull the drive out of a broken computer and put it in another computer to access the files. I just want it to be plug and play.
- mordae 5mo agoThat's called LUKS2 and it's the default on Linux. You just type passphrase on boot. It's not tied to the motherboard.
- archerx 5mo agoWhat if you forget the passphrase after not using it for many years and you suddenly need a file on the drive?
- slashdave 5mo agoPrint it on a piece of paper and put it in a lock box.
- Terr_ 5mo agoBetter still: LUKS allows you to set up multiple entry keys, so use two, either of which will grant access to the drive. * Your preferred memorized passphrase and will never be written down anywhere. * A random key you can print and store in a box somewhere. Then if your backup paper gets lost, you can revoke/replace it without having to abandoned your memorized favorite.
- slashdave 5mo agoYep. You can also put your key on a usb drive that can be read on boot. Just choose a good quality one....
- 5mo ago
- seanieb 5mo agoAt what point will Security professionals start turning down roles that involve “securing” MS Products? I’m already at this point. Securing Microsoft products is busy work while waiting to have it undercut by the next wave of MS’s insane tech debt and greed. And now backdoors!
- microtonal 5mo agoAs opposed to iOS, which does iCloud backups that are not E2E encrypted by default, so that law enforcement can request your chats (except Signal because they opt out), browser history, etc.? You can enable ADP for E2E encrypted backups, but it's probable not going to help you much, because the people you are communicating with likely didn't. This is not to defend Microsoft, more to say that all these companies were part of PRISM.
- seanieb 5mo ago> This is not to defend Microsoft But you are defending MS, conflating a bunch of things, mainly full disk encryption and cloud backups. There's a big difference between Apples cloud backup which has documented behavior and a backdoor. I'm also fairly confidant in Apple's full disk encryption, they've gone to court to defend it. There also a lot more data points we can use to judge Apple vs Microsoft on privacy and security, and MS comes out looking bad.
- microtonal 5mo agoI think my message wooshed. I was not comparing disk encryption and iCloud backups. My point is that insecure defaults are Apple and other's alternative to backdoors. They give plausible deniability ("how is someone able to recover their data if they lost their credentials and we used E2E?"), while at the same time satisfying law enforcement, because the vast majority of people is not aware of them. Another example is WhatsApp on Android, by default when backups are enabled, they are stored unencrypted in Google Drive. A good counter-example is Signal, which opts out of backups on iOS and Android and the only option is to do E2E backups to their own servers. I'm also fairly confidant in Apple's full disk encryption, they've gone to court to defend it. FWIW, in the last leaked report, iPhone was not an issue AFU for Cellebrite (macOS is most likely even easier due to looser security): https://discuss.grapheneos.org/d/14344-cellebrite-premium-july-2024-documentation https://discuss.grapheneos.org/d/14344-cellebrite-premium-ju...
- embedding-shape 5mo agoSeems this traces back almost a week, from Nightmare-Eclipse who is the researcher who found this: Tuesday, 12 May 2026 - "Here are the links, yes, two vulnerabilities this time [YellowKey] [GreenPlasma] [...] Next patch tuesday will have a big surprise for you Microsoft" Wednesday, 13 May 2026 - "I can't wait when I will be allowed to disclose the full story, I think people will find my crashout very reasonable and it definitely won't be a good look for Microsoft." Author's blog: https://deadeclipse666.blogspot.com/ https://deadeclipse666.blogspot.com/ First post in March 2026 is "[...] someone violated our agreement and left me homeless with nothing. They knew this will happen and they still stabbed me in the back anyways, this is their decision not mine." I'm not sure what to make of it, is this someone essentially "leaking" things from the inside? Sure sounds like it, and others are able to reproduce the results.
- krisbolton 5mo agoI read it as the author is / was going through the vulnerability disclosure process with Microsoft and they're annoyed for unclear reasons and decided to publicly disclose, rather than being an insider.
- mr_mitm 5mo agoHow would that leave them homeless?
- BLKNSLVR 5mo agoTitle sounds conspiratorial, but it lines up well with the controversy around TrueCrypt's discontinuation which, I believe, specifically called out BitLocker as an alternative to use in future.
- otakucode 5mo agoThat was my immediate first thought. "Oh, is Bitlocker Not Safe Anymore?"
- ekjhgkejhgk 5mo agoI'm not aware of the connection between truecrypt and bitlocker, want to enlighten us?
- akersten 5mo agoLong time ago TrueCrypt suddenly and abruptly shut down with a vague goodbye message saying "everyone please move on and use bitlocker instead" Prevailing theory is they were pressured to put in a backdoor and couldn't disclose it, so they had to make a seemingly ridiculous statement (because who in their right mind would trust bitlocker) to call attention that "something is very wrong"
- gruez 5mo ago>so they had to make a seemingly ridiculous statement (because who in their right mind would trust bitlocker) to call attention that "something is very wrong" Alternately, they don't want people to rely on abandonware for security. Also, despite the conspiracy theories of backdoors I'm not aware of any bitlocker exploits that work on TPM + pin, which is the intended "secure" configuration[1]. All exploits rely on TPM-only (ie. ez-mode), which is basically the security equivalent of running https/ssh without certificates and blindly accepting whatever keys shows up. [1] https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/planning-guide https://learn.microsoft.com/en-us/windows/security/operating...
- 5mo ago
- deleted 5mo ago[deleted]
- markant 5mo ago"Security professionals generally recommend avoiding reliance on any single encryption system and instead evaluating well-reviewed full-disk encryption alternatives such as VeraCrypt". If they put a backdoor into FDE it would make more sense to advise people to stop using windows at all and using Linux instead. If they put a backdoor in FDE you can be sure there is not just one backdoor in the operating system itself. You shouldn't trust proprietary software at all. You shouldn't even trust open source if it isn't properly audited.
- tptacek 5mo agoI don't use Microsoft products generally but not with even with your computer would I run VeraCrypt.
- MrZander 5mo agoWhat? Why?
- majorchord 5mo agoThey don't know why because there isn't a good reason to distrust them.
- recursivegirth 5mo agoEver since the TrueCrypt fiasco years ago, I have no trust in that brand.
- rokkamokka 5mo agoFiasco? You mean where they voluntarily shut down rather than compromise themselves? Or are you referring to another matter?
- michaelt 5mo agoPresumably when the authors of TrueCrypt declared “Using TrueCrypt is not secure” If I trust them to provide my FDE software, I certainly trust them when they say I shouldn’t use it.
- zb3 5mo agoThis doesn't surprise me at all. Microsoft is a Chinese company and Chinese companies have to work with the government on such matters. Oh sorry, I meant an US company, whatever..
- dboreham 5mo agoAnother way to look at this is that Microsoft, Google, Apple, et al are in the business of providing products and services to regular people, for a low cost. This means they end up providing ways to escrow keys, recover locked accounts and so on that are weak. Not because they want to provide back doors for TLAs but because to provide strong security would be so expensive they couldn't meet the price point for regular customers. If, for example, MS only provided disk encryption that relied on a smart card or a memorized strong passphrase at boot/wake, they'd go out of business providing support to people who forgot their passphrase and being sued by people who lost their data.
- jsmith99 5mo agoThis doesn't sound bitlocker specific, sounds more like a login bypass. If you rely on TPM without PIN then it gets decrypted automatically. This should be fine normally as attackers shouldn't be able to get past login screen. But this exploit shows a way allegedly to get a unrestricted shell in the recovery environment. The researcher claims a way to bypass PIN too but hasn't revealed it.
- 14 5mo agoProbably since disclosure didn't result in a bounty may as well sell it to someone who would pay.
- pixel_popping 5mo agoWell I doubt anyone would be surprised with a backdoor in MS product, there have been many of them already, I frankly doubt anyone with "disk encryption" on Windows would think that it's NSA-proof (or script-kiddy clever, as shown in this article :))
- majorchord 5mo ago> there have been many of them already source: trust me bro
- mschuster91 5mo ago> The vulnerability may also work without a USB drive if the FsTx files are copied to the Windows EFI partition and the encrypted disk is temporarily disconnected from the system. After placing the FsTx folder, an attacker would need to reboot a BitLocker-protected machine, enter the Windows Recovery Environment, and follow a specific sequence of inputs. At the point where you're able to mount the EFI partition and effectively modifying the bootloader, it's game over anyway - just run `manage-bde -unlock`, you already have to be root to mount the EFI partition.
- m3kw9 5mo agoThat should be the fastest way to make them patch it.
- pessimizer 5mo ago> Security professionals generally recommend avoiding reliance on any single encryption system and instead evaluating well-reviewed full-disk encryption alternatives such as VeraCrypt. What does this even mean? Nobody is using multiple encryption schemes on top of each other, are they?
- dboreham 5mo agoI've heard this before, so what I think it means is this: If you want to encrypt some data that gets stored persistently somewhere on your machine, rather than invent an application-specific encryption scheme for that data alone, instead use a mainstream full-partition encryption mechanism, then store the data as plaintext within said partition.
- majorchord 5mo agoBut how is that not relying on a single encryption system?
- patzentango 5mo agoI just digged into the exploit a little bit more and what it does it targets BitLocker in TPM only mode. That means that there is no preboot authentication or anything. What happens is secure boot validates the boot chain and the TPM gives out the encryption keys by itself. When you have physical access, it doesn't really make a difference. If there is a stick you can boot from and drop into an emergency shell or if you have to buy a $5 microcontroller and solder it to certain pins on the main board to sniff the TPM keys. What Microsoft is doing here in general they are selling something that is not secure. They are selling it as as full disk encryption but it's not. Someone who can flash a flash drive with an exploit and drop to a shell and use it to browse and copy files. Can also just buy that microcontroller and watch your YouTube with you How to solder. So the "exploit" isn't The problem here the problem is the false sense of security that Microsoft is selling.
- kro 5mo agoUbuntu also released TPM based FDE a few versions ago. I had these thoughts then and decided against using it. Typing my passphrase on boot is muscle memory and gives me simple security I can trust. Also can recover data without my mainboard. Maybe a hybrid (secureboot-TPM+phrase) slot for day to day to also prevent against evil maid attacks, and another slot with a backup passphrase would be acceptable.
- gruez 5mo ago>Typing my passphrase on boot is muscle memory and gives me simple security I can trust. It's not an either-or. You can combine TPM with passwords which makes it far more secure than password alone. A TPM can enforce password guessing limits, otherwise a password needs to be absurdly long to be secure against GPU bruteforcing attacks. It also prevents someone from swapping out the bootloader with a backdoored version that steals your passwords. >Also can recover data without my mainboard. You're supposed to keep a backup of the encryption key when using TPM, in case it fails.
- kro 5mo agoSounds good - which software supports this? Specifically I'd prefer if it would do a composite key derivation in-time rather than "just a pw prompt but TPM has the full key"
- kryogen1c 5mo agoFrom: https://infosec.exchange/@wdormann/116565129854382214 https://infosec.exchange/@wdormann/116565129854382214 >In a normal WinRE session, you have a X:\Windows\System32 directory that has a winpeshl.ini file in it >However, with the YellowKey exploit, it looks like Transactional NTFS bits on a USB Drive are able to delete the winpeshl.ini file on ANOTHER DRIVE Interesting. I dont know about this environment - some kind of naive file handle contructing/passing? But then, why require a key press during winre reboot? I wonder how patachable this is. The thousands of winre thumb drives are certainly out of reach; maybe the bitlocker side update the access permissions? Would it require unenc/reenc? Seems like lots more to follow
- gruez 5mo ago>The thousands of winre thumb drives are certainly out of reach; maybe the bitlocker side update the access permissions? Would it require unenc/reenc? The part that isn't mentioned is that the win re is privileged because windows stores a decryption key in the TPM that allows win re to decrypt the disk even without the recovery key. That's why the attack requires win re in the first place, rather than booting into an ubuntu live cd or whatever. This also means you don't have to patch all the winRE thumbdrives out there because their secureboot signatures can simply be revoked, meaning they can't pass TPM validation anymore, therefore they won't be able to decrypt any disks.
- steve1977 5mo agoThen I guess it is fair to call this a backdoor indeed.
- bri3d 5mo ago> This also means you don't have to patch all the winRE thumbdrives out there because their secureboot signatures can simply be revoked, meaning they can't pass TPM validation anymore, therefore they won't be able to decrypt any disks. WinRE runs internally, not from a thumb drive, which is why the bootloader will unseal the disk for it (just like if you have a systemd recovery set up on a Linux distribution). It doesn't have a separate key or anything, it's just allowed to use the "main" one, by design. Microsoft just need to patch the WinRE partition in a normal Windows Update to fix the NTFS transaction log driver; no Secure Boot revocation or TPM-related changes are necessary (which is good for them, because _that_ would be a disaster). By and large this whole thing is orthogonal to BitLocker overall; boot-time unsealed BitLocker is vulnerable to any post-bootloader auth bypass by design, and this is a goofy post-bootloader auth bypass bug.
- layer8 5mo agoBetter writeup: https://infosec.exchange/@wdormann/116565129854382214 https://infosec.exchange/@wdormann/116565129854382214 The published exploit doesn’t affect Bitlocker with a PIN, without which Bitlocker isn’t secure anyway. The original author claims they have an exploit that also works with a PIN, but hasn’t provided any proof of that.
- anal_reactor 5mo agoAssuming that the PIN version claim is true, it's interesting to think why they would've released a nerfed useless version rather than the PIN version. I have some ideas but they're completely baseless.
- qingcharles 5mo agoAnd there is a level above PIN with Bitlocker too, you can have a USB stick with a key on it which you use only during boot. I would imagine that is secure from this attack as the data isn't even stored on the device (I hope).
- deleted 5mo ago[deleted]
- briffle 5mo agoDoes your company require the pin? Or more importantly, does the company that your company pays for Cyber insurance require the pin? I have never seen a company where they require the pin for bitlocker.
- deleted 5mo ago[deleted]
- elictronic 5mo agoIt is a mandatory requirement for many Department of Defense Contractors. It matters what systems your company interacts with here creating the requirement. The bigger ones just mandate it to save headaches.
- peapicker 5mo ago
- deleted 5mo ago[deleted]
- motohagiography 5mo agoThe real problem with a Bitlocker backdoor or weakness is that when a laptop gets stolen or lost, in most regulated organizations, the criteria for legally declaring and disclosing a breach pivots on whether it was protected by disk encryption. If it's a backdoor, that's a serious fraud against their customers.
- bigyabai 5mo agoThis doesn't make much sense. Almost every single organization using Bitlocker knows that it's backdoored. It's like Push Notifications or SMS, warrantless surveillance is the norm and you don't get to opt-out. Nobody's IT department is waking up in cold sweats at the idea of the Fed stealing their data, it's part and parcel with using Windows services. If you really think this will be prosecuted as fraud, then you'll be shocked by how American courts handle these sorts of things.
- motohagiography 5mo agoif you have ever dealt with a regulated institution, they have an obligation to publicly report lost and stolen devices that contain PII/PHI as a breach, and the people whose data was on the device must be notified. It's a huge deal that has board level involvement when it occurs. The ONLY control that mitigates this risk is disk encryption, and it is perniciously misleading to ship a sabotaged product on which these legally consequential decisions get made around the world- based on the specific assurance the product is designed and marketed to provide. If true, it is a specific outrage against the laws of several countries, medical and other research ethics, public health, and the social contracts people have with their institutions. If MS is given impunity for this, a lot of regulation is not worth the paper it is written on. before arguing further, I recommend looking at the breach notification sections of the laws in these major economies: https://www.dlapiperdataprotection.com/ https://www.dlapiperdataprotection.com/
- bigyabai 5mo agoI commented because I've worked with regulated institutions where FDE was standard across the org. Bitlocker was laughed at whenever you mentioned it by name, there was not a single engineer I met that took it seriously (even the Windows daily drivers). Microsoft Windows is consistently identified as the weakest link for securing sensitive data, one job even had a no-fly policy for Windows laptops in case they were misplaced in luggage. So remind me how Microsoft was reprimanded for merging Dual_EC_DRBG support into Windows Vista? Or how they were punished for turning over Bitlocker keys to US law enforcement? It never happens. The regulation isn't worth the paper it's written on, and it hasn't been for well over a decade now: https://en.wikipedia.org/wiki/NOBUS https://en.wikipedia.org/wiki/NOBUS
- lifis 5mo agoSeems bullshit, apparently it only works with TPM-only mode, which is obviously insecure (it relies on neither the OS nor the hardware being exploitable, on a random Windows PC...), and not worth building a backdoor for. The way one would backdoor something like Bitlocker is to encrypt the disk encryption key with a (post-quantum) public key for which only the backdoor owner has the private key for, and then put it on a place on disk that is unused by the filesystem.
- polar 5mo agoPrevious discussion: https://news.ycombinator.com/item?id=48130519 https://news.ycombinator.com/item?id=48130519
- tamimio 5mo agoYou should always assume that US/european corporate protections are backdoored, now MS, a couple days ago we knew about whatsapp, and I would also include all corporate “secure or encrypted” promises, so I would warn against signal, proton, and the likes. This is the work of NSA, providing a “secure” platforms and push it everywhere to get adopted, providing false sense of security, while depreciating the none bugged ones, few weeks ago verascript developer -Mounir Idrassi- complained about having their account blocked, same with wireguard facing similar issues, and if you find it hard to believe, GPG author -Zimmerman- was harassed by the gov because he wrote the encryption and encryption was considered munition, so he was exporting munition!
- pregnenolone 5mo agoLots and lots of smattering around here. If anything, this is a secure boot flaw (and partially TPM), but that is a separate conversation. Also, it's been known for years that TPM based encryption should always be protected with a PIN for truly sensitive data: https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/countermeasures https://learn.microsoft.com/en-us/windows/security/operating... The author claims to be able to bypass TPM + PIN protection, but I seriously doubt it because that would require breaking or exploiting the TPM itself. Perhaps the author was referring to existing fTPM flaws but even then, brute-forcing the PIN would still be required because on BitLocker, the wrapped VMEK depends on the PIN, which brings me to the "backdoor" topic. As I have already mentioned, exploits have been found in AMD fTPMs in the past (https://arxiv.org/abs/2304.14717 https://arxiv.org/abs/2304.14717). This flaw is particularly severe on Linux/cryptenroll because the TPM returns the actual FVEK, unlike BitLocker, where the VMEK itself depends on the PIN. This cryptenroll flaw has been known for years and remains unfixed on cryptenroll (https://github.com/systemd/systemd/pull/27502 https://github.com/systemd/systemd/pull/27502). Yet, I see no one yelling and crying "backdoor", or accusing Lennart of being compromised. Cryptography, especially when combined with hardware security, is inherently not easy — and people make mistakes.
- utopiah 5mo agoRight, but proprietary software is still consider a serious option for security and privacy? What a joke.
- bzmrgonz 5mo agoThis is why I have trust issues with anything Microsoft. They keep burning bridges... And well, lots of Corporations keep trusting them. I guess they deserve each other.
- ChrisArchitect 5mo ago[dupe] 3 days ago OP https://news.ycombinator.com/item?id=48129789 https://news.ycombinator.com/item?id=48129789 https://news.ycombinator.com/item?id=48114997 https://news.ycombinator.com/item?id=48114997 https://news.ycombinator.com/item?id=48130519 https://news.ycombinator.com/item?id=48130519
- SilverElfin 5mo agoDoes this mean every corporate windows laptop can basically be exploited to extract confidential information?
- tavavex 5mo agoOnly if: - The device isn't PIN-protected (doesn't ask for a Bitlocker password on startup) - It runs a vulnerable version of Windows (apparently anything after 10 and before whatever version Microsoft will probably patch it in)
- fortran77 5mo agoThis is a serious bug! I've just enabled TPM+PIN on all my Windows Machines (you need a PIN before the boot sequence starts) and enabled BIOS PINs (though those are easily circumvented) and Secure Boot (again, you can get a signed WinRE and still to this exploit). The TPM+PIN setting has no PoC, but the creator hints that it's possible even with this....
- VimEscapeArtist 5mo agoAnyone remember “Using TrueCrypt is not secure as it may contain unfixed security issues”? ;)
- Sarky 5mo agoAm also thinking about TrueCrypt/VeraCrypt. Most likely more secure encryption solution... Well, definitely more secure after this debacle.
- Moiracoetzee36 5mo ago[dead]
- Moiracoetzee36 5mo ago[dead]