Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Hard to gage whether on Windows one has access to these APIs without being an Administrator.


I’m a total security noob, but I’d wager that privilege escalation is a piece of cake relative to key extraction from a TPM.


Not on fully secured Windows with Device Guard, Credential Guard, HVCI and mitigations on it is not.

The defaults are lax garbage though.


The article says "authenticated user".




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: