this post was submitted on 22 May 2026
224 points (100.0% liked)
PC Master Race
21205 readers
1151 users here now
A community for PC Master Race.
Rules:
- No bigotry: Including racism, sexism, homophobia, transphobia, or xenophobia. Code of Conduct.
- Be respectful. Everyone should feel welcome here.
- No NSFW content.
- No Ads / Spamming.
- Be thoughtful and helpful: especially when new beginners have questions.
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
lol
Microsoft:
Chaotic Eclipse posted the following with the disclosure of Yellowkey:
Additional info:
And as response to this:
They posted:
I have to say, i'm a fan.
Edit: The story so far would probably be well suited for an anime adaption. I hope we learn someday what shit MS pulled to make our friendly neighborhood security researcher so pissed that they started a one-person-crusade against one of the largest IT companies in the world.
Even better, they posted this last week:
https://github.com/Nightmare-Eclipse/MiniPlasma https://deadeclipse666.blogspot.com/
Would you happen to have a source link for those claims? I'd like to forward them to a few organisations I work with, warning them that devices currently lost/stolen/left unsupervised despite having TPM+PIN configured will have to be considered compromised even if a future patch comes out.
it's the second link, https://deadeclipse666.blogspot.com/ - The entry is from May 13, titled "We're doing silent patches now huh, also a quick note about YellowKey", the second part is from May 14, titled "Important updates regarding YellowKey and GreenPlasma". They are the one who found the vulnerabilities, PoC for RedSun, BlueHammer, YellowKey, GreenPlasma and MiniPlasma are on GitHub @ https://github.com/Nightmare-Eclipse
Thank you - it appears I stopped reading just one comment short of that, assuming that the "TPM+PIN is insecure" was a new comment, and not expecting it deeper down in the past.