Slide to Unlock by Solstad
Slide to Unlock by Solstad

This year we’ve seen cracks in Windows 11 BitLocker, VeraCrypt developers losing their ability to distribute their software on Windows, and Apple removing encryption support from the HFS+ filesystem. We’ve also seen some cases where public outcry and awareness were able to reverse some of the corporate decisions that removed the freedom of users to run secure software. There was a time when people in tech stood against government mandated keys under doormats12. Yet in today’s surveillance age, every big company seems like a willing participant in the coming technocracy.

BitLocker

Earlier this year, a security researcher who goes by Nightmare Eclipse found a means to bypass BitLocker encryption on Windows 11 and Server 2025, claiming it looks suspicious enough that it was likely an intentional backdoor by Microsoft34. Some people claim using a Trusted Platform Module (TPM) and boot pin prevents this exploit5. The original author has claimed TPM+PIN was exploitable, but he didn’t publish the proof of concept6. A few weeks later, Nightmare Eclipse published another BitLocker bypass that affected users who used Defender Offline Scan75.

Nightmare Eclipse was criticized for not responsibly disclosing such a major vulnerability, to the point where Microsoft threatened legal action against the developer8. In response, Eclipse claimed Microsoft had ignored his previous disclosures and deleted the account he had used to report them9. Several other researchers and developers also spoke up about how Microsoft Security Response Center (MSRC) had a history of closing legitimate reports and silently patching vulnerabilities, not giving credit to the original reporters and refusing to pay out bug bounties101112.

VeraCrypt and WireGuard

VeraCrypt, an open-source disk encryption system based on TrueCrypt, had their publishing account for Microsoft Windows terminated in March, removing their ability to publish updates13. Tools like VeraCrypt require kernel-level implementation, and users get scary red boot screens if they try to disable verification for these low-level drivers.

This policy change by Microsoft affected other open-source security projects, such as the popular VPN protocol WireGuard14. Microsoft claimed this was due to new requirements of mandatory account verification for partners in their hardware drivers program15, but developers claimed they completed these new verification requirements and were still locked out of their accounts anyway16. Microsoft VP Scott Hanselman publicly responded, stating he was actively working to restore the accounts for WireGuard and VeraCrypt17 and that “Not everything is a conspiracy sometimes it’s literally paperwork18.”

VeraCrypt was forked from the TrueCrypt project after it was very suddenly discontinued by the original authors. TrueCrypt’s project page put up a very cryptic message encouraging users to switch to their operating system’s native encryption19 and included instructions for enabling BitLocker20. Some have wondered if shutting down the development was a type of warrant canary; a response for a National Security Letter21. A TrueCrypt author claimed at the time that forking the project was “impossible222324,” and yet here we are over a decade later with VeraCrypt being fully maintained and actively developed.

MacOS and Extended Filesystem Encryption

Apple announced that macOS 28 will drop support for HFS+ encrypted volumes2526 and posted a support article indicating users should back up their data and migrate to APFS encryption27. What’s interesting is that they’re not dropping support for their legacy filesystem entirely, just versions of it that are encrypted. It begs the question, is support being dropped because the previous filesystem had strong encryption? Is Apple trying to move users to formats that aren’t really secure, allowing for their own backdoors to be used at government requests?

AMD Hardware

AMD recently removed support for Transparent Secure Memory Encryption (TSME), also known as Memory Guard, from their consumer processors. These came via updates to their processor firmware packages used on various operating systems, including Windows and Linux. Due to public outcry over the removed feature, AMD did eventually reinstate memory encryption2829.

Conclusions

Each one of these stories individually could have a completely benign explanation. Many companies are trying to tighten security in the new era of large language models and tools that make it easier to find security issues and vulnerabilities. Some developers and companies may want to drop unmaintained code to reduce attack footprints, such as the case with Apple and legacy filesystems. However, all of these stories coming so close together, back-to-back within weeks of each other, suggest a different picture.

I don’t believe a Microsoft VP when he claims the VeraCrypt and WireGuard situations were a “paperwork” issue18. Microsoft has aggressively made it impossible for normal consumers to set up Windows 11 without an Internet connection or Microsoft account during their initial setup. Local accounts on Windows 11 require looking up specific terminal commands as if they were game cheat codes. Meanwhile, companies like Discord are requiring government ID for some of their users30, and many governments are pushing legislation for mandatory ID verification for web services and operating system use under the lie of protecting children313233. It’s obvious these laws have nothing to do with children and are really designed to uniquely identify and track Internet usage for everyone, tying your identity to every action taken both online and offline.

I think we’re seeing security in major parts of the tech industry intentionally being eroded. Strong open-source encryption systems are being stifled in exchange for broken tools from big tech companies that have zero interest in user privacy. There seems to be a concerted effort to remove all real encryption, security and privacy from consumer software. This doesn’t seem like incompetency mistaken for malice. This seems intentional, and I predict we’ll continue to see more stories in the coming months and years. I expect more exploits and backdoors in major tools specifically geared around mass data collection, removing data privacy and removing anonymization. It’s been happening for years and now it’s accelerating.

  1. The Risks of Key Recovery, Key Escrow, and Trusted Third-Party Encryption. 27 May 1997. Abelson, Anderson, Bellovin, et. al. 

  2. Keys under doormats: mandating insecurity by requiring government access to all data and communications. 17 November 2015. Abelson, Anderson, Bellovin, et. al. Journal of Cybersecurity, Volume 1, Issue 1, September 2015, Pages 69–79. https://doi.org/10.1093/cybsec/tyv009

  3. YellowKey. NightmareEclipse. Project NightCrawler. Retrieved on 18 July 2026. Original Archived from Github 

  4. Two more public disclosures, it will never stop. 12 May 2026. deadeclipse666 

  5. Re: BitLocker. 23 June 2026. madbrain. Slashdot. (comment)  2

  6. We’re doing silent patches now huh, also a quick note about YellowKey. 13 May 2026. deadeclipse666. 

  7. GreatXML a bitlocker bypass that seems to only work if you ever had Defender Offline Scan. 10 June 2026. deadeclipse666 

  8. Microsoft under fire for threatening security researcher with criminal investigation. 29 May 2026. Franceschi-Bicchierai. Yahoo Tech. 

  9. July 14th. 23 May 2026. deadeclipse666. 

  10. “We will ruin your life” -Microsoft. 1 June 2026. ThePrimeTime. 

  11. Last time I dealt with MSRC I found a command injection vulnerability present for a decade in context menus, not highly critical but still exploitable. (see my talk Shift Happens) MSRC did not reward a bounty nor did they attribute a CVE to this finding because this “doesn’t…. 28 May 2026. @podalirius_. X. 

  12. My last submission to MSRC was for a Device Guard bypass. I learned my lesson from prior drawn-out submissions, so I included a 90 day window this time. MSRC responded saying that it met their bar and they would fix it, but asked me to withhold disclosure well past 90 days because they needed a few extra months to fix it. I agreed on the condition that they issue a CVE, to which they agreed. After the agreed-upon Patch Tuesday a few months later, I couldn’t find any mention in the CVE list, so I reached out to MSRC to inquire. It turns out - they changed their minds, deciding it did not meet their bar for servicing, yet they patched it anyway… 28 May 2026. @GabrielLandau. X. 

  13. VeraCrypt / Forums / General Discussion: Project Update. 30 March 2026. idrassi. SourceForge. 

  14. @garymarks: Thank you for the feedback. Judging by the fact that other projects like WireGuard are affected, I don’t think my move to Japan has anything to do with it. There seem to be an internal Microsoft policy that triggered this issue at large scale and there lack of communication and feedback made things worse.. 9 April 2026. idrassi. Sourceforge. 

  15. Action Required: Account Verification for Windows Hardware Program Begins October 16, 2025. 1 October 2025. NatachaC. Tech Community Microsoft. 

  16. Microsoft account verification fiasco halts critical OSR updates: tech giant scrambles to restore access. 10 April 2026. Naprys. Cybernews. 

  17. Microsoft responds after WireGuard, Windscribe, and VeraCrypt accounts get locked. 9 April 2026. Cubbins. PiunikaWeb. 

  18. Hey I love dumping on my company as much as the next guy, because Microsoft does some dumb stuff, but sometimes it’s just check emails and verify your accounts. Not every “WTF micro$oft” moment is a slam dunk. I’ve emailed VeraCrypt personally and we’ll get him unblocked. I’ve…. 8 April 2026. @shanselman. X.  2

  19. TrueCrypt. 29 May 2014. SourceForge. Archive 

  20. Enabling BitLocker. TrueCrypt. SourceForge. Retrieved 19 July 2026. 

  21. Encryption canary or insecure app? TrueCrypt warning says use Microsoft’s BitLocker. 29 May 2014. Smith. CSO Online. 

  22. TrueCrypt Author Claims That Forking Is Impossible. 19 June 2014. timothy. Slashdot. 

  23. Here is the note I sent to the only (alleged) Truecrypt dev still answering emails, along with his/her response. pastebin.com/RS0f8gwn. 16 June 2014. @matthew_d_green. X. 

  24. I am sorry, but I think what you’re asking for here is impossible. I don’t feel…. 16 June 2014. Pastebin. archive 

  25. macOS 28 Will Drop Support For Encrypted Mac OS Extended Volumes - Slashdot. 10 July 2026. BeauHD. Slashdot. 

  26. PSA: macOS 28 will drop support for encrypted Mac OS Extended volumes - 9to5Mac. 8 July 2026. Mendes. 9to5Mac. 

  27. About support for encrypted Mac OS Extended disks in macOS 28 or later. 7 July 2026. Apple Support. 

  28. Following User Outcry, AMD Reinstates Memory Encryption In Consumer CPUs. 22 June 2026. BeauHD. Slashdot. 

  29. Following user outcry, AMD reinstates memory encryption in consumer CPUs. 22 June 2026. Goodin. Ars Technica. 

  30. Discord’s Disturbing Ties to Global Surveillance - ID Verification, Palantir, & Thiel. 14 Feburary 2026. Gamers Nexus. 

  31. HW News - DRAM Antitrust Lawsuit, ID Verification, USA Wants 5% of OpenAI, Sony Drops Discs. 10 July 2026. Gamers Nexus. 

  32. Brazil Law: All OS’s Have 13 Days to Add Age Verification. 4 March 2026. The Lunduke Journal. 

  33. New Federal Law to Require Age Verification on All Operating Systems. 15 April 2026. The Lunduke Journal.