Skip to main content


A security researcher says Microsoft secretly built a backdoor into BitLocker, releases an exploit to prove it


cross-posted from: poptalk.scrubbles.tech/post/41…

A researcher known as "Nightmare-Eclipse" recently released YellowKey, a security vulnerability that allegedly enables a full bypass of BitLocker's full-volume encryption. The researcher described YellowKey as one of the most "insane" flaws they have ever encountered and has also accused Microsoft of potentially embedding a legitimate backdoor in BitLocker's data protection system.

To no-one's surprise

https://www.techspot.com/news/112410-security-researcher-microsoft-secretly-built-backdoor-bitlocker-releases.html

in reply to Scrubbles

A second backdoor. Windows also uploads your BitLocker keys to Microsoft's servers by default, just in case somebody needs to get in later.
in reply to Scrubbles

The legally have to because of the US Cloud Act.

Every single US company has a backdoor because of this.

in reply to themurphy

And this just proved why it's impossible to have a backdoor