A researcher known as “Nightmare-Eclipse” recently released the YellowKey, a security flaw that allows BitLocker encryption to be completely bypassed. The researcher describes YellowKey as one of the “craziest” flaws he has ever encountered and accuses Microsoft of possibly incorporating a legitimate backdoor into BitLocker’s data protection system.
According to the researcher, YellowKey seems unusual for a security flaw. Nightmare-Eclipse reports that the vulnerability can be replicated by copying an attached “FsTx” folder to a USB drive formatted with a Windows-compatible file system, such as NTFS, FAT32, or exFAT.




