YellowKey reportedly works in Windows 11, Windows Server 2022 and 2025, but not in Windows 10.

  • Optional@lemmy.world
    link
    fedilink
    English
    arrow-up
    180
    arrow-down
    1
    ·
    21 hours ago

    YellowKey can be triggered simply by merely copying some files to a USB stick and rebooting to the Windows Recovery Environment. We tested this ourselves, and sure enough, not only does it work, it bears all the hallmarks of a backdoor, down to the exploit’s files disappearing from the USB stick after it’s used once.

    • humanspiral@lemmy.ca
      link
      fedilink
      English
      arrow-up
      37
      ·
      17 hours ago

      100% certainty of backdoor. Is bitlocker developed outside of MSFT? Would seem to need MSFT cooperation to implement.

      • humanspiral@lemmy.ca
        link
        fedilink
        English
        arrow-up
        17
        ·
        16 hours ago

        Bitlocker was developed entirely inside MSFT. Upon further review, there is a chance that this is all somewhat normal behaviour. Part of MSFT safeOS to make it convenient to recover bitlocker access, and update windows.

        • Leon@pawb.social
          link
          fedilink
          English
          arrow-up
          12
          ·
          7 hours ago

          And be able to easily comply with law enforcement requests for decryption.

          Ergo, the encryption is actually worthless.