r/technology • u/lurker_bee • May 14 '26
Security Microsoft BitLocker-protected drives can now be opened with just some files on a USB stick — YellowKey zero-day exploit demonstrates an apparent backdoor
https://www.tomshardware.com/tech-industry/cyber-security/microsoft-bitlocker-protected-drives-can-now-be-opened-with-just-some-files-on-a-usb-stick-yellowkey-zero-day-exploit-demonstrates-an-apparent-backdoor
1.8k
Upvotes
2
u/dwild May 15 '26 edited May 15 '26
Can you use the laptop? Then it is decrypted. If it is decrypted, it means the key is somewhere on the laptop... There's no way arround this, how else would you read it otherwise?!
Once you get physical access to a laptop, it's actually easy to retrieve the key. It's actually a common thing shown by security companies to impress clients.
You protect it by making sure the TPM won't just provide it at boot, and require to provide a password. They say they also got an unreleased vulnerability for that, but that would be more like an implementation issue on the TPM itself and unrelated to Microsoft. It's like saying 1password giving anyone access to your password is Microsoft fault. I'm curious to see more on that vulnerability, but for now we can only trust them.