Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Seems this traces back almost a week, from Nightmare-Eclipse who is the researcher who found this:

Tuesday, 12 May 2026 - "Here are the links, yes, two vulnerabilities this time [YellowKey] [GreenPlasma] [...] Next patch tuesday will have a big surprise for you Microsoft"

Wednesday, 13 May 2026 - "I can't wait when I will be allowed to disclose the full story, I think people will find my crashout very reasonable and it definitely won't be a good look for Microsoft."

Author's blog: https://deadeclipse666.blogspot.com/

First post in March 2026 is "[...] someone violated our agreement and left me homeless with nothing. They knew this will happen and they still stabbed me in the back anyways, this is their decision not mine."

I'm not sure what to make of it, is this someone essentially "leaking" things from the inside? Sure sounds like it, and others are able to reproduce the results.



I read it as the author is / was going through the vulnerability disclosure process with Microsoft and they're annoyed for unclear reasons and decided to publicly disclose, rather than being an insider.


How would that leave them homeless?


Many brilliant people have serious mental health issues that preclude their ability to regulate their emotions and act maturely in serious situations e.g. responsible vulnerability disclosure.

I've watched genius-level IQ people get fired time and again because they don't know how to work with others at a basic kindergarten level.


To be honest if I got fired in a mean or unfair way I'd definitely hit back at my employer in such a manner if I'd have the ability to. I'm unlikely to have that though as I'm not aware of any saucy company secrets. But if this is what happened I think it's pretty justified.

The secret here seems to be that Microsoft caches the key somewhere even when it's supposed to be only in the TPM! That's a pretty big revelation IMO.


> The secret here seems to be that Microsoft caches the key somewhere even when it's supposed to be only in the TPM!

Not what happened here (I reserve my judgment wrt the promised TPM+PIN exploit).

In the default TPM-only mode of BitLocker, the secret is in fact in the TPM, which will (as instructed by Windows upon key creation) release it to the correct OS running on the correct computer. Notably not in the picture is any user-provided data: measured boot is the only protection. It is only the correct programming of the OS that makes it request an account password (completely unrelated to the disk-encryption cryptography) before letting the user poke at the disk, which the OS can at that point already decrypt.

Well, turns out the programming is such that if you ask politely it’ll just pop an Administrator(?) shell.


> Not what happened here (I reserve my judgment wrt the promised TPM+PIN exploit).

Yes this is the one I'm referring to.

I have noticed it myself, it has happened to me that my system rebooted to install updates and it did not pass through the blue TPM pin entry screen at that point. That was a big red flag for me. A normal reboot always does that, even a 'hot' reboot.


Bitlocker can be suspended, and will be unprotected until the next reboot. Then it will resume (and presumably re-lock to the current state)

A good or corporate BIOS/etc. updater will do this to avoid requiring a recovery at the next boot


> Bitlocker can be suspended

But the files on the disk must still be decrypted somehow. The key must be stored somewhere.

According to this: https://windowsforum.com/threads/pause-bitlocker-before-bios...

> BitLocker is now suspended, which means the drive remains encrypted, but Windows temporarily stores the unlock information so firmware changes won’t immediately trigger recovery.


> A normal reboot always [forces the TPM pin entry screen], even a 'hot' reboot.

In TPM-only mode, I only see the screen—which asks for an recovery key that serves an alternative to the TPM-borne secret, not for whatever you are calling the “TPM PIN” here—whenever I update the firmware or the bootloader (the latter from the other side of the dual-boot setup). Otherwise it boots straight to the login screen, which meshes with the measured-boot-only theory of operation I’ve described above. There’s nothing nefarious in this part, even if I think it exposes an unwisely large attack surface (e.g. the USB stack). I suspect you simply reboot so rarely you’re never hitting the happy path.


No I have the explicit PIN turned on. That means it requires a Pin entry on each boot. It's not the recovery screen though it looks similar. It's also not a password that's then hashed. It unlocks the TPM with a short pin, the number of attempts is limited by the TPM itself so that it doesn't get brute forced.

This is not a standard option, I think it can only be set through a group policy.


> To be honest if I got fired in a mean or unfair way I'd definitely hit back at my employer in such a manner if I'd have the ability to.

I knew a contractor that developed a habit of not paying his workers for a short time. After people started walking off job sites with his tools and showing up at his house demanding to get paid, he magically found the money to pay them.

It’s pretty unsurprising how vindictive regular people rapidly become when they’ve been ripped off.


Reporting wrongdoing to the ones doing it doesn't work. Perhaps they relied on Microsoft a bit too much for their livelihood and are just beginning to reevaluate their decisions. It's not so rare for brilliant people to live a life of the mind and not pay enough attention to their material conditions. But defining that as "serious mental health issues" is such a cheap shot.


> Reporting wrongdoing to the ones doing it doesn't work.

Most large companies — including Microsoft [1] — have an internal affairs call center where you can anonymously report issues of malfeasance — assuming that's what happened here.

[1] https://www.microsoft.com/en-us/legal/compliance/sbc/report-...


There is, sadly, no place for non-standard ICs in corpos nowadays. HR will enforce that.


Emotionally immature people tend to be a liability, not an asset. Therapy can help, but they first need a willingness to do better.


Yeah I'm getting a lot of pressure to be a "team player" lately. I've told them over and over I'm not capable of that and that has never been a problem before. But we have a hipster new VP who is really pushy and wants to generalise everything.


If you worked for me and you said you're not capable of being part of a team I'd immediately start looking to replace you.

You might be a 100x rockstar developer. You might even be the best software engineer in the world.

But the vast majority of good software is built by teams of people. It doesn't matter how good you are if you can't play nice with others.

I'd rather have a team of "merely" good engineers than one "rockstar" creating a toxic work culture. Fuck that noise.


"Not being a team player" doesn't mean the person is a nuisance, but they can be an introvert who has a limited interaction budget and can work silently and efficiently otherwise.

This generally means the person might not leave their cubicle much or give feedback frequent enough, but this doesn't mean they are not motivated to help others or share knowledge. One can approach and ask a question and get tons of help immediately.

How I know? That's me. I look like a cave dweller from a distance, but I'm not. The only difference I have is human interaction sometimes drains me a lot, so I just concentrate and work, yet everybody get their help immediately if they need them.

Also, no, I don't bite or belittle people. On the contrary.

Assuming the worst in others is bad. If I worked with you, I'd be looking for somewhere else the moment I found out how you think about me.

Remember. People don't leave bad jobs, but bad managers.


I have worked with lots of introverts and my empirical observation is that the introversion/extraversion axis is completely orthogonal to whether or not someone can be a team player.


You require both team players and "rockstar" individuals. It's not one or the other or a competition, because they do different things.

Yes if you put a someone who can't work on a team on a team and expect team work then that will not work. But that's obvious, so then don't do that. Expecting a homogeneous workforce isn't realistic or optimal.


>You require both team players and "rockstar" individuals.

Hard disagree.

Some of the best, most successful, and most impactful projects I've ever been on had no "rockstars" at all.

People who refer to themselves as rockstars is a huge red flag.


I'm not a software engineer at all. And I tend to take on projects nobody else wants because they are too complicated or esoteric.

And I didn't say I'm not capable of being part of a team. Just that I need to have my own responsibilities within a team. I can't deal with micromanagement or excessive coordination like 'standups' every day.


In other words, you want replaceable cogs rather than human beings.


Yeah you've completely misread this. The phrase "not being a team player" is a euphemism for someone not willing to do dubiously unethical or illegal (or things that go against internal company policy) things in support of a low level supervisor or manager's wishes. Or more favourably, someone who's unwilling to do things outside of what he's actually paid for or to do things unpaid (or outside working hours etc.). Also known as wage theft.

The guy saying that he has been accused of "not being a team player" isn't literally quoting his management here. He's summarizing that his immediate supervisors don't like him because he's unwilling to enter in some patronage like relationship with them.

The fact that you gave the benefit of the doubt to some faceless employer here instead of an actual person recounting his experiences is really sad and maybe ought to be reason for you to rethink your biases to jump to the conclusion that this guy is a toxic loner. Sounds like you're projecting hard here from some other experience.


That is also a thing yeah. It's not really unethical or illegal but our VP has a huge preference for snazzy glitzy projects and never wants to tackle the problems that cause real pain in the organisation because they are not spectacular and don't make him look good. And yes I bring that up whenever it comes into play. I'm definitely not an order-follower.


> I've told them over and over I'm not capable of that

I can relate and empathize. And also provide this suggestion based on my own similar experience: if you can't provide evidence (e.g. doctor's diagnosis) that you are "special" or "not capable of that", then they don't have to care and will take steps to force you out. I wish you all the best.


Here in Europe it's different, we have more rights. Unfortunately I don't have an official diagnosis but I'm definitely neurodivergent. I've been meaning to get one but it is difficult.


I was once (12 years ago) told: "they debate, they decide, we deliver" along with other "teamwork" pablum. This evil has been with us for a very long time, unfortunately.


IC = Independent contractor (I assume?)



individual contributor. Someone who has no one reporting to them.


Individual contributor i.e., non-management


Nonsense. there are way more accommodations for people who wouldn't have had a place 20 years ago... those accommodations have changed what a "standard IC" is. There never was a place for run-of-the-mill geniuses who couldn't be bothered to spend a few hours researching P2P (Person to Person) protocols. They were always pushed off to small companies where the risk was much lower. This hasn't, won't, and shouldn't change. If that makes you salty, I got some things I'd recommend you research.


Adults pay rent in money, not feelings. The answer to “how could Microsoft leave you homeless?” is “by not paying you”, not some bizarre “by making you feel so bad you lose your house, which you pay for with good feelings”


This is an oddly passive-aggressive comment when a much more likely read is they were relying on the funding and the large tech company did what large tech companies do and started moving slowly.

And I can see others already blaming them for relying on the vulnerability for living expenses, but if we can hold the hyper-rationalization for a second, we shouldn't be against the person who expected an organization with more money than God to uphold a deal for relative peanuts, right?

Like yes we all get that large orgs make spending $5 very hard, many claps for being the in-group, but their frustration would be understandable.


I'm supposed to feel bad that Microsoft didn't immediately wire him an advance on the bounty before validating anything? Have you ever tried to get anything corrected with a corporate payroll department? Try three months minimum.

It's like suggesting someone was relying on a lottery ticket to payout to survive.


I tried to be as coddling with my language as possible.

Acknowledged how orgs work, separated blaming the org from sympathizing with their reaction, tried to separate the prudence of their actions from the sticky situation they'd still be left in by the orgs actions...

But it was for naught: people are really ingrained in a weird "might-makes-right" model of corporate operations. "Larry Ellison is a lawnmower" was supposed to be a jeremiad but now it's more like a guiding principle that we browbeat anyone for questioning.


Yes and that's bad. Saying it's bad doesn't make it not-bad, it just makes it still bad but now we know it's bad.


> we shouldn't be against the person who expected an organization with more money than God to uphold a deal for relative peanuts, right?

You're assuming that there was a deal that wasn't upheld. I don't think we have enough information to assess that. This person's blog posts do read as being somewhat unstable. There's even someone in the comments seemingly genuinely trying to be helpful: "Just wondering if you’re BiPolar (like me) and see a different reality than what is real. Been there."


Presumably, not paying out for these bugs which often take weeks of research to find.


Who in their right mind bets on bug bounties to cover their basic needs? They should be highly employable with these kind of skills.


> Who in their right mind bets on bug bounties to cover their basic needs?

Someone with a vulnerability worth as much as a two bedroom apartment?


If you take the statement at face value, that does not appear to be the case. If you don’t take it at face value, the underlying presumptions might be a lot of why they may not be employable.


Someone who doesn't have better options?


If you have those sorts of skills with a computer, you will have other options


Really depends on your background doesn't it? You could have convictions, be sanctioned, have visa problems, or all kinds of things that are not easily solvable.


Indeed, and this guy's personality seems a little "difficult" which might make the interview process short. I've known people with insane skills who have such weird personalities that they never get hired. Doing remote bug bounty stuff is a blessing for them.


To say nothing of mental health issues.


Or poverty. Or addiction.

Or that entire holy trinity.


Please let me know when finding a job in software engineering in 2026 is feasible for everyone with ‘computer skills’.


The guy doesn’t just have „computer skills“ if he found this.


Good luck convincing a HR automaton not looking at your resume for the job unposting of that.


Come on, with these skills you could convince someone to give you a job if you’re on the streets otherwise. You might not be a senior engineer in the exact thing you want but you won’t be on the streets.


It's not about your skills. It's about how well you can play the HR metagame. This inversely correlates with actual job skills.


Convincing someone, especially an HR person, has very little to do with computer skills.


Good with computers and good with people/job search/finances are not the same thing, and are often inversely correlated.


King Terry was living proof this is not true.


Oh hell, no. Does anyone remember Sandboxescaper/Polarbear? Very skilled researcher, but also crashouts and mental problems.

Had a job at MSFT once, but is now struggling to earn money at all and is posting heart breaking stuff on Twitter. https://x.com/WeirdQuadratic

Hope she finds a way out and a more stable and fun job in the future.


Then you pay him since you see the value he’s creating so clearly.


This is a strange argument. I don't have the capital, desire, or skills to employee this guy, or anyone really.

Me not hiring someone doesn't mean the skills aren't valuable.


We are, quite notably, in a huge hiring crisis where vast numbers of programmers and researchers can't even get interviews. It really is not that simple


people with values different from yours, presumably


This is one it those answers that seems on the surface like it contains insight but on closer inspection it’s vacuous.

This could be rewritten as “because they aren’t you”, which is true but not a meaningful or educational answer.


Sure sounds like rhetorical questions or attacking the messenger. Someone can think the bounty industry is going to reward them for actually being exceptional and not look soon enough for other options then pivot to a stance that should give them some quick job offers. If I thought I found an intentional back door I would not engage with an embargo system from the same vendor but I am also not them.


> Someone can think the bounty industry is going to reward them for actually being exceptional and not look soon enough for other options then pivot to a stance that should give them some quick job offers

Sure. And that’s a meaningful answer to the question.

“people with values different from yours, presumably” is a condescending nonanswer.


This entire thread is generally weird.

If someone has this kind of exploit and can't get a bug bounty for it, and desperately needs the money, he can sell it for 100k+ in a shady black market


It was about as meaningful as the question it was answering.


https://github.com/BigPolarBear1/The_story

I've been pretty convinced this is SandboxEscaper for awhile now.


Previously discussed numerous times on HN, like: https://news.ycombinator.com/item?id=48130519

Whether this is a backdoor or not boils down to whatever your usual proclivities about "bug or backdoor" are; it's not like "if microsoft = 1 hack bitlocker" like the tech press seem to love to report.

This is a bug in the NTFS transaction log replay functionality in the Windows Recovery Environment WinRE, where it will read NTFS transaction logs from an external volume and apply them to the mounted filesystem. This allows the attacker to perform an authentication bypass against WinRE. With BitLocker without PIN or Password, _any_ authentication bypass becomes a disk encryption bypass, since the disk is unsealed by the bootloader (this architectural "flaw" is true for Linux with the same configuration, as well, like Ubuntu installed with their newish Hardware Disk Encryption checkbox in the installer).

In lieu of additional evidence, whether you think the NTFS transaction log issue is a planted backdoor or a simple enumeration bug depends on your conspiracy theory level, like most things in exploit development. To me, it seems like a plausible bug. The weaknesses in boot-time unseal are well known and obvious and this is just one of many, so I don't see it as an earth-shattering revelation, although it is a fun bug.


It's very strange that the same component exists in Windows without the issue, though. Like the author, I'm finding it difficult to come up with reasons why they'd be different.


WinRE ending up with a different version of fstx.dll in it seems like a pretty standard Microsoft (or any other big company) thing to have happen? Again, it all comes down to whether you think the drift was a malicious internal fork or a simple mistake. I will say that the functionality being different makes it an inferior backdoor in many ways; especially in Windows land vulnerability researchers are obsessed with binary diffing, and any delta internally would be more likely to be discovered as a backdoor in review too (ie - “hey maybe we should update fstx in winrt finally, let’s review the drift to make sure there’s not going to be a regression, wait a second why did xyz employee add this suspicious looking code”).

A fun next step would be to look at different fstx versions to see if it’s just something that was patched or refactored out at some point. At that point it could be a patch-door (ie an organic bug where the patch was held back by interference), but again, that would be a crappy setup due to the propensity for Windows vulnerability engineers to use binary diffing - if you had the exploit and the power to hold back the patch, it would be way better to hold it back everywhere.


I'm not necessarily suggesting they intentionally made the dll different for RE. The possibility that RE was maliciously backdoored is certainly possible, but there are three plausible other possibilities I can see:

1. A bug was introduced that affects both, and the bug never make it back into the 11 branch

2. There's conditional logic in RE that triggers the issue

3. 11 introduced new behavior that never make it to RE, causing the bug

The fact that 10 is seemingly unaffected is telling. #2 seems very unlikely, because it suggests new conditional logic was added and not tested. #3 seems unlikely because I can't understand why the binaries would be different anyway. #1 seems unusual because it suggests there's no canonical source of truth for the code, which feels very unlikely for bitlocker of all things (where you want everything speaking the same language).

If there's any benign explanation, I suspect it's likely due to incompetence. This feels like such a strange problem to have. I suspect the follow-ups you suggest are going to happen very soon and we'll know more.


The author says he is able to use a similar vuln to bypass the PIN requirement. Most certainly a backdoor if true.


I discussed this at length in the last thread: https://news.ycombinator.com/item?id=48137059

We know how PIN-locked BitLocker works, and it requires unwrapping using a key sealed behind a TPM PIN policy and stretching it using the PIN itself. So we can deduce that this would require that:

* The attacker was able to bypass the TPM PIN sealing policy _and_ brute-force the stretching applied to the decrypted key. Brute-forcing the stretch is plausible on a "lots of expensive stuff" timeline but not an easy attack. Bypassing TPM PIN policy across multiple platforms would be something quite incredible. Given that TPMs are implemented by multiple vendors across multiple fundamental architectural approaches, and aren't based on a universal reference implementation, it would be rather bizarre to find a mistake in many or all of them.

* There is a secret volume key stored on a volume which can be decrypted by another mechanism. This would be a backdoor, but seems vanishingly unlikely given the amount of research which has been applied against BitLocker historically.

* The attacker is at some point able to inject something which allows them to observe the victim applying the PIN. There could be an attack here but it isn't nearly as interesting.


> Most certainly a backdoor if true

If Microsoft wanted a backdoor they don't need to put it in the WinRE environment. They can sign payloads that will pass the TPM and unlock bitlocker, without needing to store anything on your disk.


Except with TPM+PIN, the TPM itself is verifying the PIN before unsealing any keys... so something else must be going on if they're telling the truth about a PIN exploit.

Maybe their alleged exploit doesn't work on a cold boot or has some other non-standard situation.


This is the most succinct, plain-English explanation I've seen to date. Thank you for posting this.


Can’t wait to read the blogpost of what have truly happened and motivated this person to expose M$ like this


[flagged]


I hear you. But, I must also admit that reading "M$" in public discourse sure makes me nostalgic for better days on the internet.


Micro$lop it is from now on :)


Yeah man we've been saying negative things about them for like 40 years must we constantly dwell on what they do wrong? It's time we find positive angles


They keep doing negative things that influence the industry and infringe upon the freedoms of hundreds of millions of people. Yes we should keep dwelling on that.


I read the parent as sarcastic. Since the mentioned the continued negative things they do.


Positive HN-appropriate angle: they're very financially successful and have been for 40 years.


>Yeah man we've been saying negative things about them for like 40 years

Well gee, I wonder why people have been saying negative things about them for so long?

Perhaps if it's been that long there's a kernel of truth to the matter.

Perhaps they're a shitty company who does shitty things selling shitty products.


From my basement in Wyoming, I stab at thee!


Micro$lop it is!


But nothing has changed. It's fair to say it's silly, jeuvenile, but it's also fair to say MS deserve absolutely no normal respect you would pay a turd. Maybe the poster actually is 12 and we all have a right to be 12 for a while. There's always a new generation discovering today what we discovered 30 years ago.


Nothing has changed? Microsoft is a huge open source contributor now, produced one of the largest open source ecosystems in use (.NET) and provides free access to the biggest open source software repositories (GitHub). Sorry to say, but believing nothing with MS has changed is deranged.


Nothing has changed except that it's even worse now than before, and the venue or arena changes every few years (os to developer tools to office to cloud etc). vscode or .net core or whatever you think is so valuable does not make MS your friend any more than giving you free IE did. Come the fuck on. It is beyond ignorant to try to make this argument. (or it's perfectly consistent with having a financial interest)

I guess if there are always new 20 year olds just discovering something, that must mean there are also always new 15 year olds that haven't discovered it yet, and 80 year olds that have gone Dawkins and lost what they had, and the just plain ignorant or unobservant with no real excuse.


No real open source contributor thinks any corporation is "their friend", whatever that means. And yet, it is undeniably true that being a Linux foundation member and contributor, producing and maintaining one of the largest programming language ecosystem and runtimes currently in use, and running the largest open source friendly source code repositories for free, would have been unthinkable under Balmer or Gates' Microsoft, and if you think otherwise, you should look in the mirror for that ignorance you mentioned.


I view it as new paint on same crappy house.

They had to do the open-source thing for .NET because of external pressure - not because they've changed.

They had to get GitHub because of the eyeballs. It's not some altruistic play.

In both cases some VPs spun it around, juked the stats and got their bonus.

The first E of EEE feels so good makes you forget the inevitable outcome. Like heroin.


> They had to do the open-source thing for .NET because of external pressure - not because they've changed.

Corporations don't have some innate "essence" that defines their nature, their behaviour is defined by internal and EXTERNAL factors, yes. So what?

The very fact that you recognize that external factors have influenced how they approach open source is a tacit acknowledgement that their behaviour has indeed changed.

> They had to get GitHub because of the eyeballs. It's not some altruistic play.

No corporation is completely altruistic, so what?


> produced one of the largest open source ecosystems in use (.NET)

Are they going to ship an official cross platform UI library any time the next century? Decades after the Java lawsuit they still ship only a crippled copy of their scrapped Microsoft JVM for other platforms.

> Microsoft is a huge open source contributor now

Aren't almost all of their contributions for integration with their proprietary technology?

> Sorry to say, but believing nothing with MS has changed is deranged.

Yes, they got worse. They maintained Windows XP for ages and you could actually feel the improvements they shipped. Windows 11 meanwhile makes me wait for them to add a robotic arm with a knife as hardware requirement, to improve the backstabbing experience.


> Are they going to ship an official cross platform UI library any time the next century?

So because they haven't produced your pet project means they haven't changed?

> Aren't almost all of their contributions for integration with their proprietary technology?

No. They didn't have to make .NET cross platform and run equally well on Linux, they didn't have to join the Linux foundation and make contributions to the Linux kernel. There are hundreds if not thousands of examples like this that would have been unthinkable under Gates and Balmer Microsoft.

> Windows 11 meanwhile makes me wait for them to add a robotic arm with a knife as hardware requirement, to improve the backstabbing experience.

Microsoft is much, much larger than just Windows. You seem to have a very limited understanding of everything they do.


> So because they haven't produced your pet project means they haven't changed?

Good to know that their flagship cross platform framework not even having an UI component rates "pet project".

> No. They didn't have to make .NET cross platform and run equally well on Linux

Which they never did, instead they renamed .Net core, which to this day isn't a feature complete replacement for .Net.

> they didn't have to join the Linux foundation and make contributions to the Linux kernel.

Given that they sell cloud products with Linux integration, yes they did?

> Microsoft is much, much larger than just Windows.

And here I thought everything they do is compensation for being tiny, I mean it is literally in the name.



He personally still owns 100m shares (per your article) and has not bailed out.

The B&MG foundation sold their remaining 7.7m shares.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: