Tuesday, 9 June 2026

Regarding YellowKey PIN+TPM

 -----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA512


A lot of you had the question of, how will YellowKey work with TPM+PIN.


It wasn't simple, it was an executable that you needed to run in WinRE that will perform all of the required work and output special transaction files. Those transaction files are then put those transaction files in the recovery partition.


Then you have to give the victim their machine back and wait for them to enter the PIN, once the PIN is entered, the machine will keep crashing using some magic you can do to the WinRE partition, once the machine enters WinRE, it will cause the transaction files to be recovered and overrite arbitrary files in the bitlocker protected volume with controllable content. I didn't release the PoC because I rely on bitlocker myself, bitlocker is great, the issue is it have to rely on retarded software to function which is a huge flaw.

-----BEGIN PGP SIGNATURE-----


iHUEARYKAB0WIQRJTvAf/AWVhAKEeb7FFoRCS0/SbAUCaiinLQAKCRDFFoRCS0/S

bHk3AQClJoP4SPtxIQIBClPaCWDB4p2qVEiONWFAYfu9WMLAnwD/dEP2XuKzPuKp

Iv3uk97oZi7wJbhzbdRGGhCAIdbT1AY=

=y3l7

-----END PGP SIGNATURE-----


5 comments:

  1. > bitlocker is great

    BitLocker isn't great. It isn't up to modern security standards, especially in comparison to other FDE alternatives such as LUKS2 and VeraCrypt. BitLocker has weak defaults: TPM-only, does not require to provide any secret; AES-128-XTS instead of AES-256-XTS; uploading of a recovery key to Microsoft's servers for users who signed in into the account, which is a direct security and even safety issue especially for US citizens. BitLocker has a single KDF algorithm which is a non-memory-hard, outdated PBKDF2, GPU/ASIC brute-forcing of which is very effective. VeraCrypt has Argon2id since 2025; LUKS2 - since long. VeraCrypt defaults to PBKDF2 but with a much higher iteration count and salt than BitLocker's; LUKS2 defaults to Argon2id. Both default to AES-256-XTS.

    macOS' FileVault uses AES-256-XTS and PBKDF2 but isn't susceptible to its brute-forcing and other common attacks due to the secure configuration of Apple's hardware. FileVault's recovery key is uploaded to the user's iCloud Keychain, but it's end-to-end encrypted, so Apple doesn't have anything unencrypted to hand over to the government unlike Microsoft, which can and did hand over plain BitLocker recovery keys to law enforcement.

    BitLocker is the weakest FDE among all of the above. Its only advantage is reliability (in comparison to VeraCrypt) and convenience, if used to encrypt a Windows installation. VeraCrypt is more prone to issues than a native FDE, no matter on which OS it is used. For average users on Windows it is better to manually configure BitLocker and store the secrets locally. For data storage on external drives no one should use BitLocker, but file-based encryption with AEAD or better FDE alternatives, all with a memory-hard KDF.

    ReplyDelete
  2. Hello Nightmare Eclipse,

    I hope it is okay to contact you directly.

    I am currently dealing with a BitLocker problem that is very important to me personally, and I would be extremely grateful if you could maybe give me an honest assessment of my situation.

    In short, I have a BitLocker encrypted data drive for which the recovery key appears to be missing. The drive contains private data collected over several years, including personal documents and photos. I have already tried to document the case as clearly as possible in a Reddit post here:

    https://www.reddit.com/r/HashCracking/comments/1tr1ndq/bitlocker_data_drive_locked_missing_recovery_key/

    I fully understand that you are busy and that there may simply be nothing that can be done. I am not asking for free recovery work or a miracle solution. I would just be very thankful for your honest opinion on whether there is still any realistic chance of getting access to the data, or whether I should accept that the data is most likely lost.

    Even a short assessment would mean a lot to me.

    Thank you very much for your time.

    ReplyDelete
  3. No rush! Is this another version of YK? Excited to see the release when you're ready.

    ReplyDelete
    Replies
    1. I think it'd be low priority, as if you lose a device the mitigation is simple: building security.

      A company that does not have building security will be vulnerable in even more easier ways: https://xkcd.com/538/

      Delete
    2. By mitigation = building security I mean like if you lose a device and it gets magically returned you probably wouldn't use it. So the building security part left is you make sure that someone don't bang into your doors, put files on your computer, wait for you to boot it, and then get the data again. So ineffective building security is the only attack vector/

      Delete

Moving to new blog, avoiding google censorship,

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Moving from blogger since google started flagging personal research blogs as "malware...