Post B57eYgHfepw2fJVwAK by h3artbl33d@exquisite.social
(DIR) More posts by h3artbl33d@exquisite.social
(DIR) Post #B57ctFmnAjKwejkjpI by h3artbl33d@exquisite.social
0 likes, 0 repeats
Another day, another hit of a clusterfuck dropped by Microslop...https://techcrunch.com/2026/04/08/veracrypt-encryption-software-windows-microsoft-lock-boot-issues/
(DIR) Post #B57ctFzuNxpRJPtDGq by h3artbl33d@exquisite.social
0 likes, 0 repeats
Oh they did the same honors to Wireguard: https://news.ycombinator.com/item?id=47687884WTAF. Gooooo #OpenBSD
(DIR) Post #B57ctGobLUNVqdbhHk by h3artbl33d@exquisite.social
0 likes, 0 repeats
@PLA_906114 Yeah - there was a bypass for BitLocker because of the rather complex design of it ("enterprise customers").A bypass. For full disk encryption. I repeat: a bypass.:flan_facepalm:
(DIR) Post #B57ctGzEhwswNcaBrU by h3artbl33d@exquisite.social
0 likes, 0 repeats
@PLA_906114 I think it was this one: https://media.ccc.de/v/39c3-bitunlocker-leveraging-windows-recovery-to-extract-bitlocker-secrets
(DIR) Post #B57ctH8o8MXcrJ3pmS by Rairii@labyrinth.zone
0 likes, 0 repeats
@h3artbl33d @PLA_906114 not just one. https://github.com/Wack0/bitlocker-attacks
(DIR) Post #B57dtFNWmrAJLXUq80 by h3artbl33d@exquisite.social
0 likes, 0 repeats
@Rairii @PLA_906114 Indeed. I am aware of the history - exactly the reason why if a Microslop desktop is a must, so is VeraCrypt. Encryption that can be bypassed shouldn't be referred to as encryption.
(DIR) Post #B57dtFpB83HcjIQvE8 by Rairii@labyrinth.zone
0 likes, 0 repeats
@h3artbl33d @PLA_906114 technically it's only the default settings that allow for attacks that lead to dumping the derived volume keyslike, if you have osdevice bitlocker key protector set to TPM+PIN+USB, the only way an attacker is deriving the volume key is by having that PIN and USB (so would require an evil cleaner attack to exploit those vulns).unfortunately almost nobody changes the settings from the defaultsand yet people have still had actual data loss due to automatic bitlocker, which should never have been a fucking thing in my opinion. MS says it's fine because the recovery key gets escrowed to MS account on login (which also gives a way for law enforcement to get it without needing exploits!), but this is never ever mentioned in setup and people log in with like school accounts that get deleted later and such...
(DIR) Post #B57eYgHfepw2fJVwAK by h3artbl33d@exquisite.social
1 likes, 0 repeats
@Rairii @PLA_906114 Yeah - I believe that it is (or was?) an option to disable the TPM in the group policy editor and enforce the combination of a passphrase + keydrive.Perhaps I am a bit much of a tinfoil hat wearer, but I do not trust BitLocker at all. I do not trust Microslop or their sloperating system. Still, need to encrypt all the things, so this is where VeraCrypt comes in for me. The least worst option.
(DIR) Post #B57evaWfETfRT1RxgG by Rairii@labyrinth.zone
0 likes, 0 repeats
@h3artbl33d @PLA_906114 as someone who has actively done bitlocker research, i can totally understand your concerns.
(DIR) Post #B57fpqC2AXfqH6cjmS by PLA_906114@illumos.cafe
1 likes, 0 repeats
One of my first interactions with encryptions was PGP, by Philip Zimmermann I wanted certain emails to be encrypted with a public private key pair combination In reading Zimmermann, documentation I noticed that there could be something wrong.Source code openness and other eyeballs were needed.## We got that in openGPGI've NEVER trusted closed source encryption schemes.I sometimes also verify if the shadow that's following me is actually mine@h3artbl33d @Rairii #InfoSec #programming #encryption #VeraCrypt #WireGuard #WindScribe #technology #microSlop
(DIR) Post #B57g2UhLOkYfNFIoQi by h3artbl33d@exquisite.social
1 likes, 0 repeats
@PLA_906114 @Rairii Indeed. At the very least: foundational technology that is supposed to protect us all should be open source. Closed source is not acceptable there, period.
(DIR) Post #B57h3njAEVBEdVLBh2 by rl_dane@polymaths.social
0 likes, 0 repeats
@PLA_906114 @h3artbl33d @RairiiAbsolutely. I kinda see the hierarchy like this:Frequently audited FOSS encryption > audited ONCE FOSS encryption > unaudited FOSS encryption > closed source encryption > closed source encryption with "new and innovative/experimental" encryption algorithms > closed source encryption with unspecified/proprietary/secret encryption algorithms.@Dendrobatus_Azureus
(DIR) Post #B57h3oIG81FkOLlDOa by Rairii@labyrinth.zone
0 likes, 0 repeats
@rl_dane @PLA_906114 @h3artbl33d @Dendrobatus_Azureus if it's popular, it will (eventaully) get researched. "closed source" can otherwise be written as "reversing skill issue"
(DIR) Post #B57h8CDj6vFFl3jR5s by Rairii@labyrinth.zone
0 likes, 0 repeats
@rl_dane @Dendrobatus_Azureus @PLA_906114 @h3artbl33d and "closed source encryption with "new and innovative/experimental" encryption algorithms" and "closed source encryption with unspecified/proprietary/secret encryption algorithms" definitely can attract reversers, if they know about it and can get the samples.
(DIR) Post #B57hNn62HyfSTEZRrM by rl_dane@polymaths.social
1 likes, 0 repeats
@Rairii @h3artbl33d @Rairii @Dendrobatus_Azureus @PLA_906114I'm not saying that novel encryption schemes are inherently bad, but "encryption math is very hard," and you can't trust the implementation, yeah.And too many times, the "new and innovative encryption scheme" is just glorified XOR/ROT13 anyway. XD
(DIR) Post #B57ieiSCu0jmwvZkEi by PLA_906114@illumos.cafe
1 likes, 0 repeats
Glorified ROT13 spawned a ROTFL 😂 here ;)@rl_dane @Rairii @h3artbl33d @Dendrobatus_Azureus