Somebody on twitter “reverse engineered” the exploit. Apparently ms shipped debug code in production. At least it’s not called Backdoor_FBI outright.
How it works: Recovery tools look for a config file called RecoverySimulation.ini on the OS drive If Active=Yes, it enables "test mode" for the recovery tools Test mode unlocks your BitLocker drive but a flag called FailRelock tells it to skip relocking cmd.exe spawns with full access to your "encrypted" drive
How it works:
Apparently they are amazing aides for the visually impaired.
full thread
Somebody on twitter “reverse engineered” the exploit. Apparently ms shipped debug code in production. At least it’s not called Backdoor_FBI outright.