this post was submitted on 13 May 2026
873 points (99.8% liked)

Technology

84623 readers
5743 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
 

YellowKey reportedly works in Windows 11, Windows Server 2022 and 2025, but not in Windows 10.

you are viewing a single comment's thread
view the rest of the comments
[–] homesweethomeMrL@lemmy.world 185 points 1 day ago (1 children)

YellowKey can be triggered simply by merely copying some files to a USB stick and rebooting to the Windows Recovery Environment. We tested this ourselves, and sure enough, not only does it work, it bears all the hallmarks of a backdoor, down to the exploit's files disappearing from the USB stick after it's used once.

[–] humanspiral@lemmy.ca 40 points 23 hours ago (1 children)

100% certainty of backdoor. Is bitlocker developed outside of MSFT? Would seem to need MSFT cooperation to implement.

[–] humanspiral@lemmy.ca 19 points 21 hours ago (2 children)

Bitlocker was developed entirely inside MSFT. Upon further review, there is a chance that this is all somewhat normal behaviour. Part of MSFT safeOS to make it convenient to recover bitlocker access, and update windows.

[–] Valmond@lemmy.dbzer0.com 1 points 2 hours ago

Normal behaviour?

-"Well it turns out we just said your data was protected, for your, ehrm, satisfaction?"

[–] Dojan@pawb.social 18 points 12 hours ago

And be able to easily comply with law enforcement requests for decryption.

Ergo, the encryption is actually worthless.