Apparently, not even TPM+PIN is safe from YellowKey.
Also, it's a twofer with the GreenPlasma zero-day local privilege escalation.
Update 5/21: Since this article was released, recommend mitigations for YellowKey and other attacks have been released, as well as a full patch for BlueHammer. Nightmare-Eclipse, a cybersecurity ...
BitLocker is intended to protect confidential data from physical attacks. The Windows Recovery Environment bypasses the protection.
A zero-day vulnerability called ' YellowKey,' which could potentially bypass Microsoft's BitLocker-encrypted drives, has been disclosed by security researcher Nightmare-Eclipse. Alongside this, ...
The IT researcher behind the "NightmareEclipse" project shows new vulnerabilities: "YellowKey" in BitLocker and privilege escalation with "MiniPlasma".
This just came across my feed. It's a blurb about a potential backdoor with BitLocker. I came across a story about this here: https://www.xda-developers.com/new ...