this post was submitted on 13 May 2026
286 points (99.7% liked)

Technology

84569 readers
4078 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
 

YellowKey reportedly works in Windows 11, Windows Server 2022 and 2025, but not in Windows 10.

top 40 comments
sorted by: hot top controversial new old
[–] Treczoks@lemmy.world 5 points 35 minutes ago

Well, Microsoft "Security" hard at work.

[–] gnufuu@infosec.pub 24 points 1 hour ago (1 children)

From their blog:

Now regarding YellowKey, lots of you are wondering how does one even find such backdoor ?

I'll tell you how, it took me more time trying to get it to work than the amount of sleep I had in two years combined. No AI involved, no help in any shape or form. I could have made some insane cash selling this but no amount of money will stand between me and my determination against Microsoft.

[...]

I can't wait when I will be allowed to disclose the full story, I think people will find my crashout very reasonable and it definitely won't be a good look for Microsoft.

Looking forward to the full story.

[–] Jako302@feddit.org 1 points 3 minutes ago

I could have made some insane cash selling this but no amount of money will stand between me and my determination against Microsoft.

There is no better motivator than pure anger and spite.

[–] Sgt_choke_n_stroke@lemmy.world 1 points 4 minutes ago

I lost 3 years of work and my research dissertation because of bitlocker. Fuck you microslop, now I do everything on Linux because of your security garbage

[–] homesweethomeMrL@lemmy.world 45 points 2 hours ago

YellowKey can be triggered simply by merely copying some files to a USB stick and rebooting to the Windows Recovery Environment. We tested this ourselves, and sure enough, not only does it work, it bears all the hallmarks of a backdoor, down to the exploit's files disappearing from the USB stick after it's used once.

[–] yesman@lemmy.world 24 points 2 hours ago

They also state the vulnerability is well-hidden, and that they "could have made some insane cash selling this, but no amount of money will stand between me and my determination against Microsoft."

based.

[–] homesweethomeMrL@lemmy.world 20 points 2 hours ago (1 children)

You’d think this would only be the 100th-or-so embarrassing security-defying bug to plague micro$oft but you’d be wrong.

It’s like we’re in a world where most people use windows to log on to facebook. Its bizarre.

[–] calcopiritus@lemmy.world 18 points 1 hour ago (1 children)

Backdoors are features, not bugs though.

[–] 9tr6gyp3@lemmy.world 29 points 4 hours ago* (last edited 38 minutes ago) (2 children)

The process is dead simple: grab any USB stick, get write access to the "System Volume Information," and copy into it the "FsTx" folder and its contents. Shift+click Restart to get Windows to the recovery environment, but then switch to holding down the Control key and don't let go. The machine will reboot, and without asking any questions or showing any menus, will drop you in an elevated command line with full access to the formerly Bitlocked drive, without asking for any keys.

~~Its dead simple to get write access to System Volume Information~~

~~Not even local admins have access to it. A local admin would have to take ownership of that folder (not recommended), but if a local admin is doing that for this exploit, they can just turn off Bitlocker rather than go through this nonsense.~~

I misunderstood the exploit. See replies.

[–] AnyOldName3@lemmy.world 29 points 4 hours ago* (last edited 4 hours ago) (1 children)

By exploit standards, that's not especially hard. I don't think there's really anything blocking accessing it at all if an NTFS volume is mounted on a typical desktop Linux distro, as it's just NTFS permissions blocking it, and they're not typically obeyed by Linux in the first place.

In the face of your edit, I see that you've misunderstood the exploit. You need write access to the System Volume Information directory of your own USB stick, not anything on the target machine. It's much easier to get access to things on a computer than it is to get access on one particular computer, and this exploit lets you jump from one to the other.

[–] 9tr6gyp3@lemmy.world 6 points 4 hours ago (1 children)

Its bitlocker encrypted. You need to unlock the disk to see System Volume Information in Linux.

[–] AnyOldName3@lemmy.world 13 points 4 hours ago (1 children)

I'll copy the bit here that I just edited into my reply after you edited the first post:

In the face of your edit, I see that you’ve misunderstood the exploit. You need write access to the System Volume Information directory of your own USB stick, not anything on the target machine. It’s much easier to get access to things on a computer than it is to get access on one particular computer, and this exploit lets you jump from one to the other.

[–] 9tr6gyp3@lemmy.world 10 points 4 hours ago

Ah yeah, I misunderstood. Thanks for the clarification.

[–] MonkderVierte@lemmy.zip 3 points 4 hours ago (1 children)

Your strike-through didn't work somehow.

[–] 9tr6gyp3@lemmy.world 3 points 4 hours ago (1 children)

I know! I cant figure it out 😂

[–] eronth@lemmy.world 9 points 3 hours ago (1 children)
[–] 9tr6gyp3@lemmy.world 1 points 57 minutes ago (1 children)

I tried without spaces too unfortunately

[–] Speculater@lemmy.world 1 points 42 minutes ago (1 children)

I think it's three tildas.

[–] 9tr6gyp3@lemmy.world 3 points 38 minutes ago (1 children)

Its two. It didn't like the exclamation mark. I removed it and it started working.

[–] Speculater@lemmy.world 1 points 36 minutes ago

Oh nice work!

[–] ChristerMLB@piefed.social 13 points 4 hours ago (2 children)

Except Microsoft doesn't have the respectability to discontinue a clearly broken product now that they've baked it into ever installaion of Windows 11 by default

[–] jqubed@lemmy.world 2 points 3 hours ago (3 children)

As in you think they were pressured into stopping development so people would switch over to BitLocker, which now appears to have a backdoor put in by Microsoft or at least one of the developers, presumably at the behest of a government?

[–] adarza@lemmy.ca 4 points 2 hours ago

there's a backdoor built right into bitlocker in the form of 'recovery keys'--and for most users, microsoft knows what they are.

[–] ChristerMLB@piefed.social 1 points 1 hour ago

The thought did cross my mind, yeah. I don't think it's quite sufficient evidence to make such a big conclusion, but both of these seem so conspicuous

[–] homesweethomeMrL@lemmy.world 3 points 2 hours ago

Yeah its Not Safe As.

Also your delivery from Flowers By Irene is waiting outside

[–] Raglesnarf@lemmy.world 1 points 2 hours ago (2 children)

if I just browsed the web and didn't play any computer games I'd be on Mac or Linux. I'm only on windows because it's familiar, works with my games (new and old), and I'm lazy

[–] lazynooblet@lazysoci.al 1 points 2 minutes ago

Truth, I feel the same way. If my pc broke tomorrow, it'd be rebuilt as Linux

[–] einfach_orangensaft@sh.itjust.works 10 points 1 hour ago (1 children)

linux is at the point where your games probably now run better on linux than on windows, simply becausr windows has become so bloated with ai spyware running in the background

[–] Raglesnarf@lemmy.world 1 points 23 minutes ago (1 children)

I agree with you. I'm just scared/lazy and don't want to take the dive. one day though

[–] Damage@feddit.it 1 points 14 minutes ago

Eh, stay on Lemmy long enough and one day you'll boot your computer and find it running Linux

[–] LodeMike@lemmy.today 3 points 4 hours ago (2 children)

What the fuck is that OG image

[–] ChristerMLB@piefed.social 5 points 4 hours ago (1 children)

a laptop that is literally cracked? :l

[–] Rentlar@lemmy.ca 6 points 3 hours ago (1 children)

Zoolander iMac

The files are IN the computer!

Which, I mean, he's technically not wrong. Files exist as data on a hard drive that exists in the computer. If you destroy the hard drive in the computer the files cease to exist.

[–] AnyOldName3@lemmy.world 2 points 4 hours ago (1 children)

A laptop that's been driven over or smashed with a hammer or otherwise crushed.

[–] LodeMike@lemmy.today 3 points 4 hours ago (2 children)
[–] TachyonTele@piefed.social 6 points 4 hours ago

Because thats what i want to do to my laptop that is stuck on the bitlocker screen

[–] MonkderVierte@lemmy.zip 4 points 4 hours ago* (last edited 4 hours ago)

Windows = PC or something, who knows.