YellowKey reportedly works in Windows 11, Windows Server 2022 and 2025, but not in Windows 10.
YellowKey can be triggered simply by merely copying some files to a USB stick and rebooting to the Windows Recovery Environment. We tested this ourselves, and sure enough, not only does it work, it bears all the hallmarks of a backdoor, down to the exploit’s files disappearing from the USB stick after it’s used once.
100% certainty of backdoor. Is bitlocker developed outside of MSFT? Would seem to need MSFT cooperation to implement.
Bitlocker was developed entirely inside MSFT. Upon further review, there is a chance that this is all somewhat normal behaviour. Part of MSFT safeOS to make it convenient to recover bitlocker access, and update windows.
And be able to easily comply with law enforcement requests for decryption.
Ergo, the encryption is actually worthless.
deleted by creator
Normal behaviour?
-“Well it turns out we just said your data was protected, for your, ehrm, satisfaction?”
I lost 3 years of work and my research dissertation because of bitlocker. Fuck you microslop, now I do everything on Linux because of your security garbage
Not to be that guy, but that’s 100% on you for not having backups of important work. It’s 3 years and your fucking research dissertation, how the fuck do you keep that all in one place?
This time you got fucked by Microsoft for having shit software. But it could have been your hardware that exploded, your house catching fire, your shit being stolen, you downloading malware from that one site you told your girlfriend you’d never visit again, shitty infrastructure causing power issues or flooding, you yourself having a nervous breakdown and nuking the thing.
Keep everything important at least in three places, one of which should be in a physically different (remote) place. Backup often, keep to the schedule and test your backups.
Jeez man, using Microsoft software and not having backups is like walking around with a loaded gun pointed at your dick. It’s all well and good till you get your dick blown off.
In the immortal words of Daniel Rutter (again): If nothing else, backups are necessary because at some point in your life you will confidently instruct your computer to destroy your data.
“If it only exists on your laptop, it doesn’t exist”
From their blog:
Now regarding YellowKey, lots of you are wondering how does one even find such backdoor ?
I’ll tell you how, it took me more time trying to get it to work than the amount of sleep I had in two years combined. No AI involved, no help in any shape or form. I could have made some insane cash selling this but no amount of money will stand between me and my determination against Microsoft.
[…]
I can’t wait when I will be allowed to disclose the full story, I think people will find my crashout very reasonable and it definitely won’t be a good look for Microsoft.
Looking forward to the full story.
Picture got me confused. Do you use a usb stick or a hammer?
Both?

BitLocker is basically malware, so who fucking cares. Far more people have it accidentally on and get locked out than people that have purposefully activated it.
Companies care
When I worked at an MSP, BitLocker cost companies thousands of dollars when it did something strange. User error has very catastrophic consequences with BitLocker and nobody that actually cares about security uses BitLocker. From my professional experience it is malware. The places where I have seen it used on purpose was because of policy bullshit and everyone agreed that it was a hindrance rather than an advantage.
And from my experience in banking, healthcare and others; every company uses bitlocker on workstations, I saw EncFS once in dozens of companies audited.
Using encryption on files systems is fine, but the Microslop Bitlocker implementation is awful. In any ecosystem that is not fully regulated BitLocker is a liability. I have had colleagues that could beat it.









