Windows is a toy OS, good enough to play video games. But many confused people think it's okay to use for critical or sensitive operations.
cybersecurity
An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!
Community Rules
- Be kind
- Limit promotional activities
- Non-cybersecurity posts should be redirected to other communities within infosec.pub.
Enjoy!
https://github.com/Nightmare-Eclipse/YellowKey
Now why would I say this is a backdoor ? The component that is responsible for this bug is not present anywhere (even in the internet) except inside WinRE image and what makes it raise suspicions is the fact that the exact same component is also present with the exact same name in a normal windows installation but without the functionalities that trigger the bitlocker bypass issue. Why ? I just can't come up with an explanation beside the fact that this was intentional.
Somebody was recently making fun of Linux vulnerabilities being found. As if Winblows is even remotely better.
I mean.. with the amount of times Microsoft has just decided to BitLocker user drives without approval and then accidentally locked people out of it with bad updates, they should be offering bugs like this to the public via tools as a means to access their old Bitlocker-trapped files.
Good reminder that if you do ever have important files encrypted and lose access to them - put the files (or drive) aside if financially viable, it will likely become accessible in the near to mid-term future via incompetence/bugs/advances.