YellowKey reportedly works in Windows 11, Windows Server 2022 and 2025, but not in Windows 10.

  • Optional@lemmy.world
    link
    fedilink
    English
    arrow-up
    186
    arrow-down
    1
    ·
    1 day ago

    YellowKey can be triggered simply by merely copying some files to a USB stick and rebooting to the Windows Recovery Environment. We tested this ourselves, and sure enough, not only does it work, it bears all the hallmarks of a backdoor, down to the exploit’s files disappearing from the USB stick after it’s used once.

    • humanspiral@lemmy.ca
      link
      fedilink
      English
      arrow-up
      40
      ·
      1 day ago

      100% certainty of backdoor. Is bitlocker developed outside of MSFT? Would seem to need MSFT cooperation to implement.

      • humanspiral@lemmy.ca
        link
        fedilink
        English
        arrow-up
        19
        ·
        24 hours ago

        Bitlocker was developed entirely inside MSFT. Upon further review, there is a chance that this is all somewhat normal behaviour. Part of MSFT safeOS to make it convenient to recover bitlocker access, and update windows.

        • Valmond@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          1
          ·
          5 hours ago

          Normal behaviour?

          -“Well it turns out we just said your data was protected, for your, ehrm, satisfaction?”

        • Leon@pawb.social
          link
          fedilink
          English
          arrow-up
          18
          ·
          15 hours ago

          And be able to easily comply with law enforcement requests for decryption.

          Ergo, the encryption is actually worthless.