YellowKey reportedly works in Windows 11, Windows Server 2022 and 2025, but not in Windows 10.
Somebody on twitter “reverse engineered” the exploit. Apparently ms shipped debug code in production. At least it’s not called Backdoor_FBI outright.
How it works:
- Recovery tools look for a config file called RecoverySimulation.ini on the OS drive
- If Active=Yes, it enables “test mode” for the recovery tools
- Test mode unlocks your BitLocker drive but a flag called FailRelock tells it to skip relocking
- cmd.exe spawns with full access to your “encrypted” drive
Does test mode unlock without the key?!? So it’s just “encrypted” with a generic key, and the unlock key is for authentication? That sounds insane, even for microsoft.
this works because the bitlocker key is stored in the TPM of the mainboard on the computer.
That is neccessary for the computer to be able to boot without entering your bitlocker password. you can configure it differently, but that is not default or super obvious to do.It always struck me as…poor…to not require a password for decryption. If you require zero knowlege from me, that means a stolen has everything inside needed to decrypt all the data.
And well, lookie there at the article!
“Ah yes, but think about how much faster they shipped that code with Copilot doing all the heavy lifting.”
- Some Microsoft exec, probably
😮💨
BitLocker is basically malware, so who fucking cares. Far more people have it accidentally on and get locked out than people that have purposefully activated it.
You have just reminded me I could use this on the laptop my mother set up like five years ago and immediately forgot the password for.
Companies care
When I worked at an MSP, BitLocker cost companies thousands of dollars when it did something strange. User error has very catastrophic consequences with BitLocker and nobody that actually cares about security uses BitLocker. From my professional experience it is malware. The places where I have seen it used on purpose was because of policy bullshit and everyone agreed that it was a hindrance rather than an advantage.
And from my experience in banking, healthcare and others; every company uses bitlocker on workstations, I saw EncFS once in dozens of companies audited.
Using encryption on files systems is fine, but the Microslop Bitlocker implementation is awful. In any ecosystem that is not fully regulated BitLocker is a liability. I have had colleagues that could beat it.
Companies care that you have access to it. The “companies that care” literally wrote the backdoor.
Finally, some good news. Now I can stop having to interact with my companies shitty outsourced service desk when I need a Bitlocker key.
Bitlocker is Temu encryption
Temu is, as Chinese netizens will tell you, full of items on a lower 4th rung of quality well below what they are used to (at least the urbanites, but I doubt farmers want to buy junk for shit they need to do). That doesn’t mean that a single-board computer you buy off it would be incapable of anything you need to do, just surrounded by stuff advertised in a misleading way to get you to buy more shit.
Their business itself has customer data well-encrypted, never sends out your email to spammers (I isolate email accounts I would notice). They have never had a single data breach.
weird bot
I manually post on these as well, they currently have only used post scheduling, haven’t set up feeds. It’s nice to hide my own accounts from each other, and if I don’t, then I’m going to forget and people will get mad that the bots are unmarked. Not your problem.
So, any comment on me pointing out the obvious racism?
The post you replied to never said “Chinese”, it said “Temu”. So you saying “Oh yeah Chinese people agree, Temu is garbage” actually proves… that it was a reasonable statement?
It still could’ve been said from a racist place or with undertones of racism, but it’s not necessarily guaranteed. Temu is garbage. Americans think so. Chinese people apparently think so.
How specious. Yes, Temu is trash mixed with treasure, but it’s the exact same garbage you pay a premium for at online or brick-and-mortar retailers, so I find it quite funny when USonians act above it. You don’t have an option for better quality that isn’t as Chinese as possible without getting ripped off, unless you need cameras or the latest graphics cards. Temu encryption is good. American corporate encryption leans very bad. Just watch some cybersecurity conferences. More than racism I’m irritated by people using terminology wrong.
Chinese people think Temu is trash and would never use it
I find it quite funny when USonians act above it
I’m going to stop talking to you now because wtf are you even on about. No one said anything about not wanting to buy Chinese goods. I specifically buy Chinese goods because at least their billionaires are kept to heel and are doing less to actively fuck over my life than Jeff Bezos.
Also no one said anything about Temu encryption but you, so again, wtf are you even on about?
Well, I’m happy to stop talking if you’re the type more interested in catfighting than even interpreting the conversation correctly. GreenBottles did in fact start off saying Microsoft is using Temu encryption. If Microsoft was using Temu encryption then their customers would be safe & they would have a record of zero data breaches. I don’t think farmers would buy anything important on Temu, I never said no Chinese person would use it. This is anecdotal from speaking to urbanites who were more interested in high-quality manufacturing for throwing some money around in the markets. Nevermind!
I’m glad you buy your Chinese stuff directly instead of through Bezos, but I hope you can see that the kids using Temu synonymously with “dogshit” are being somewhat racist. Since this isn’t based off a comparison with durable good from Amazon or the supermarket. Amazon support just isn’t worth the markup. It’s informed by propaganda spreading through unconventional means such as gore websites plastered with Russian and Chinese industrial accidents or hit-and-runs from the 2000s. Things change, and when that change is accompanied by a meme where a Chinese company is used as an adjective meaning dogshit, I think, well, the advertising firms that these Fortune 500 companies employ would feel quite chickenshit if they got beaten to the punch by natural slang developments. They’d be saying gee, I wish we got them talking like this five years before.
They have never reported a data breach.
Fixed that for you. Same goes for most companies though - the abscense of a publicly known data breach does not mean it hasn’t happened, with or without said company’s knowledge.
of course there’s a back door. You motherfuckers think they’ll TPM secure boot lock file manage SECURTYYYY and not let five eyes waltz in whenever they fucking well please?
Closed source security mechanism has backdoor
More news at 9
Lmao, remember when Microsoft wouldn’t make a backdoor for the US government? https://mashable.com/archive/fbi-microsoft-bitlocker-backdoor
I wonder what favor the government traded for this. Or maybe what threats were made to Microsoft…
Gee Mr Gates, that’s a nice monopoly you’ve got there. It sure would be a shame, if that anti-trust lawsuit the AG is researching were to happen to it…
I wonder what favor the government traded for this. Or maybe what threats were made to Microsoft…
Probably none; don’t forget, the majority of Lose11 is vibecoded
You think they just offered a backdoor to the US government unprompted? They just changed their mind? I know technically there isn’t evidence of it being for the government, but like… Come on. Something like this isn’t a bug or AI hallucinating
Maybe it’s just a coincidence! Maybe those files just randomly do that lmao. Including deleting themselves!
Lol, imagine if they made that defense. “This was the result of an AI hallucination!”
There was a reason for disappearance of TrueCrypt
TrueCrypt was forked into VeraCrypt, which is still maintained.
What reason? It was broken?
Suddenly dev resigned and posted bizzare post that read like he was at a gunpoint, recommending bitlocker instead of truecrypt
It was very likely compromised by NSA requiring a backdoor or weakened encryption that could be cracked by the US. There’s a long story that’s pretty interesting if you want to hit the rabbit hole
No, it worked so well that the governments didn’t like it.
Buttlocker
Is this an analogy that you can take bitlocker…

Anything that isn’t open source can’t be secure. That doesn’t mean that everything open source is secure though.
Anything human made is prone to all the errors humans make. At least with Open Source, there are more eyes that can spot mistakes, potentially even provide a fix.
Sure, that means bad actors can find them too. But closed source doesn’t prevent that: Raising the hurdles may slow them down, but they if they have a financial incentive to keep trying, it won’t stop them as effectively as it stops the type of people who would do a responsible disclosure instead of selling the information.
I guess LUKS is safe.
Microslop can’t even claim incompetence. The way this reads, the function is intended as a back door.
Picture got me confused. Do you use a usb stick or a hammer?
Both?

Why do they call it “drive encryption” when it does not need a user-provided password or other key?
TPM microslop magic.
What’s even funnier is that we already have TCG, ISE, and SE drives that hardware encrypt AES256 by design, so you still get at least an instant delete option if you never bother to set a key.
Windows wants to double screw you over by never telling you it added a key, and then leaving you dead in the water if your TPM breaks, and then also failing to maintain their own TPM requirements making it completely useless lol.
good news for those being locked out of their data by one of the faulty windows 11 upgrades!









