AMAZINGINDEX.COM 日报快照
55.9
VOL. 2026.05
2026.05.18
← 返回 2026.05.18 日报
日报快照 · Daily Snapshot
NO. 018

BitLocker 被曝内置后门

#ARTICLE HackerNews 2026.05.18
推荐指数 55.0 NO. 018 · 2026.05.18
发布2026/05/17Score431Comments176

安全研究员公开指控微软在 BitLocker 中秘密植入后门,并发布漏洞利用代码作为证据。对依赖 Windows 设备加密的 AI 创业公司和远程办公团队构成直接安全威胁,需立即评估数据保护方案。

BitLocker 被曝内置后门

这个指控如果属实,意味着企业级全盘加密方案存在系统性信任危机。BitLocker 此前被大量 AI 创业公司用于保护训练数据和模型权重,尤其是租用云服务器或远程办公场景。

建议立即做两件事:一是审计现有设备加密方案,考虑迁移到 VeraCrypt 或硬件级加密;二是检查云端实例是否依赖 Azure 的托管磁盘加密,评估是否需要叠加应用层加密。研究员已放 exploit,PoC 代码流通后针对性攻击风险会快速上升,窗口期可能只有几天到几周。

意见分歧 119 条评论

核心争论:BitLocker强制加密与用户体验的冲突,以及加密必要性的分歧

superkuh

As long as Microsoft will continue to use dark patterns to convert local accounts to online accounts and automatically, without user consent, encrypt the storage drives preventing any computer use until the user goes to aka.ms and through the hoops, this is a good thing. No one should have their dat

mynameisvlad

You only need to use the aka.ms link if you lost your recovery key. That feature also can be disabled without disabling Bitlocker as a whole.

superkuh

How would a user that never set it up in the first place have a recovery key? I honestly am asking and don't know. I recently (last week) had to drive over to a parent's house and "fix" their (pre-online accounts) win 11 computer used for sewing because it had become a blue screen saying aka.ms was

替代方案: dm-crypt
查看原文 →