Mystery Microsoft bug leaker keeps the zero-days coming

(theregister.com)

84 points | by e12e 3 hours ago

8 comments

  • ndiddy 1 hour ago
    I think the Bitlocker "vuln" is a good reminder not to use vendor provided encryption for any sensitive data. https://github.com/Nightmare-Eclipse/YellowKey/ You load a specific file onto a flash drive, plug it into a Bitlocker encrypted computer, reboot it while holding a key combination, and it pops up a command prompt with full access to the encrypted volume. There's no way this isn't a backdoor.
    • aiscoming 20 minutes ago
      this exploit works only if you dont use a PIN/password for your Bitlocker and the volume automatically unlocks

      so it gives you access to an encrypted volume which automatically unlocks anyway

      the only difference is that it immediately gives you root access to the volume instead of having to go through the Windows login procedure - this might be a stolen laptop you dont have an account on

      • ndiddy 2 minutes ago
        The author claims the exploit also works with TPM+PIN, he just hasn't released the PoC:

        > Second thing is, No, TPM+PIN does not help, the issue is still exploitable regardless, I asked myself this question, can it still work in a TPM+PIN environment ? Yes it does, I'm just not publishing the PoC, I think what's out there is already bad enough.

        https://deadeclipse666.blogspot.com/2026/05/were-doing-silen...

    • otterley 53 minutes ago
      > I think the Bitlocker "vuln" is a good reminder not to use vendor provided encryption for any sensitive data

      I don't think that's true. Some vendors have a better track record than others. Nobody's popped the storage encryption on iOS or MacOS devices yet AFAIK; and the fact that it's tied to a hardware secure element makes it pretty strong.

      • Veserv 1 minute ago
        Ah yes, the bizarro world where systems are normally unhackable so the default assumption is impenetrable security and you need to prove they are insecure.

        Thank god this is not the world where things get hacked all the time and where any claim of meaningful security is a extraordinary claim that demands extraordinary evidence and proof before credibly asserting it, but everybody just ignores that part and just pinky promises it and people believe them.

      • thefz 46 minutes ago
        You mean aside from the NSA? https://en.wikipedia.org/wiki/PRISM
        • otterley 37 minutes ago
          I don't see anything on the linked page that supports a conclusion that NSA has successfully broken the encryption at rest of an Apple device's storage since they introduced the secure element.

          Care to share a quote?

          • ffsm8 14 minutes ago
            Prism targeted network communication to my knowledge, hence the data wouldn't be siphoned from at rest encrypted devices. Instead it would've been leaked before it was copied to that local encrypted device, whenever it was transmitted over the wire. Eg when your background task uploaded it to iCloud or similar.
  • NDlurker 1 hour ago
    Oh cool. My brother's old laptop is locked. Maybe this will help
    • Charon77 57 minutes ago
      Only affects win11
      • NDlurker 15 minutes ago
        Haha I texted him about this and he said he already re-installed Windows. Bad timing. It was just a couple weeks ago he told me about this.
      • taspeotis 23 minutes ago
        Windows 11 is almost 5 years old at this point
  • purpleidea 1 hour ago
    It's so obvious that many of the bugs being found are/were most likely M$ backdoors.

    There doesn't seem to be any other plausible explanation. The reckoning needs to come and people need to stop using their products for good.

    Would love a whistleblower to explain which part of the government or company forced it.

    • anonymars 1 hour ago
      Haven't there been heaps of vulnerabilities cropping up all over recently, including CopyFail and Dirty Frag?
  • __alexander 2 hours ago
    So weird that GitHub requires a login to view their BlueHammer repo.

    https://github.com/Nightmare-Eclipse/BlueHammer

    • tsujamin 1 hour ago
      That warning also doesn’t render right on my iPhone (the buttons are overlapping slightly), and I don’t recall seeing it on other repos. Is it new/bespoke?
  • aussieguy1234 1 hour ago
    Could the Bitlocker vulnerability be a backdoor mandated by some government agency?
  • NordStreamYacht 1 hour ago
    Laid off Microsoft researcher?
  • ChrisArchitect 1 hour ago
    Related:

    YellowKey Bitlocker Bypass Vulnerability

    https://news.ycombinator.com/item?id=48114997

  • quxuejun 1 hour ago
    i think so~