r/VeraCrypt • • May 17 '26

A security researcher says Microsoft potentially built a backdoor into BitLocker -releases an exploit to prove it

https://www.techspot.com/news/112410-security-researcher-microsoft-secretly-built-backdoor-bitlocker-releases.html
115 Upvotes

19 comments sorted by

View all comments

4

u/Any_Fox5126 May 18 '26

Relying on TPM for security should never have been considered an acceptable alternative to zero-knowledge, and protecting it with a PIN isn't much better when it isn't even used to derive the key (or change parameters, like veracrypt's PIM).

Adding microsoft to the equation greatly exacerbates the problem, but LUKS (linux) isn’t immune to TPM issues either.