Post B6Uicr6qGY7DePHy9Q by RLFP@infosec.exchange
 (DIR) More posts by RLFP@infosec.exchange
 (DIR) Post #B6UYOzYf3ezoG43GIy by cR0w@infosec.exchange
       1 likes, 2 repeats
       
       Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices.I know people here probably don't want to rehash the disclosure discussion for the 683,547,329th time, but fuck Microsoft and this passive aggressive bullshit trying to frame their own interests as "best practices" in a vuln mitigation publication. Your shit is getting torn apart. Act like you've been there before because we all know you have.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585
       
 (DIR) Post #B6UYOzxTZOqTV1f4z2 by djsumdog@djsumdog.com
       1 likes, 1 repeats
       
       It's not a CVE. It's an obvious backdoor that didn't exist in Win10. It was planned and it was intentional.
       
 (DIR) Post #B6UicqXOOLl7sShetc by 0x00string@infosec.exchange
       1 likes, 1 repeats
       
       @cR0w violating coordinated vulnerability best practices.NO MICROSOFT YOUR PERSON PREFERENCES ARE NOT BEST PRACTICES, CHOKE ON 0DAY YOU SCUM FUCK PIECES OF SHIT I HOPE THEY ALL HAD A BAD DAY BECAUSE OF ITAND IM SORRY HOW DARE YOU TALK ABOUT ANYONE ELSES BEST PRACTICES WHEN YOU SHIPPED A FUCKING CUCKOO EGG BACK DOOR YOU FUCKING WASTES OF FINGERS
       
 (DIR) Post #B6Uicr6qGY7DePHy9Q by RLFP@infosec.exchange
       2 likes, 1 repeats
       
       @0x00string @cR0w
       
 (DIR) Post #B6UjYrwbJuCL2HA54q by Rairii@labyrinth.zone
       0 likes, 0 repeats
       
       @djsumdog @cR0w @0x00string as someone who's involved with bitlocker security research, and who has looked into this issue as well, i wouldn't call it a backdoor. less malice, more incompetence. basically a combination of a legitimate bug allowing arbitrary file delete when booting into winpe, and a debug codepath in winpe initialisation that requires a specific file to not be present.it didn't exist in win10 because the component with the file delete bug was only introduced in Germanium (Win11 24H2). new privileged component getting some eyes on it leading to vuln discovery doesn't automatically mean backdoor.
       
 (DIR) Post #B6Ul3nAHEvDt8yrqim by 0x00string@infosec.exchange
       1 likes, 0 repeats
       
       @Rairii @djsumdog @cR0w wait how did i get here this wasnt my post :think_bread:
       
 (DIR) Post #B6Ul3nLGa40th40cqm by Rairii@labyrinth.zone
       0 likes, 0 repeats
       
       @0x00string because i wanted to put this reply on your rant elsewhere in the thread too, the next best thing was tagging you in
       
 (DIR) Post #B6UlDnge9ZVbeumSFk by 0x00string@infosec.exchange
       1 likes, 0 repeats
       
       @Rairii oh i dont think it was an intentional backdoor, when i said "cuckoos egg backdoor" i was referring to that book cliff stoll wrote where he had strawberry milkshakes over finding someone using an emacs bug and then some german kids got set on fire in the woods later.i was trying to express that they were so incompetent as to ship such a bug, not that they did it on purpose. that would be giving too much credit here.
       
 (DIR) Post #B6UlVxBNaTY0K0oNqS by Rairii@labyrinth.zone
       0 likes, 0 repeats
       
       @0x00string ah, i apologise for not parsing your post correctly then :)
       
 (DIR) Post #B6UvmI58ePpzJaJz4C by troed@swecyb.com
       1 likes, 0 repeats
       
       @Rairii @djsumdog @0x00string @cR0w