logoalt Hacker News

ndiddytoday at 3:11 AM3 repliesview on HN

I think the Bitlocker "vuln" is a good reminder not to use vendor provided encryption for any sensitive data. https://github.com/Nightmare-Eclipse/YellowKey/ You load a specific file onto a flash drive, plug it into a Bitlocker encrypted computer, reboot it while holding a key combination, and it pops up a command prompt with full access to the encrypted volume. There's no way this isn't a backdoor.


Replies

aiscomingtoday at 4:20 AM

this exploit works only if you dont use a PIN/password for your Bitlocker and the volume automatically unlocks

so it gives you access to an encrypted volume which automatically unlocks anyway

the only difference is that it immediately gives you root access to the volume instead of having to go through the Windows login procedure - this might be a stolen laptop you dont have an account on

show 1 reply
zuzululutoday at 6:16 AM

How does Bill Gates keep getting away with this

otterleytoday at 3:46 AM

> I think the Bitlocker "vuln" is a good reminder not to use vendor provided encryption for any sensitive data

I don't think that's true. Some vendors have a better track record than others. Nobody's popped the storage encryption on iOS or MacOS devices yet AFAIK; and the fact that it's tied to a hardware secure element makes it pretty strong.

show 3 replies