Support in other languages: 
Showing results for 
Search instead for 
Do you mean 
Reply
Blue Screen Again
wibbler
Posts: 4
Registered: ‎07-16-2010
Location: UK
0
Accepted Solution

X301 Secure Erase with new BIOS

Hi there,

 

I switched to an Intel X18-M SSD on my X301 some time ago. I noticed that the new BIOS was released with Secure Erase functionality some time ago. As I was going to rebuild my laptop today, I thought I would give it a go. Turns out that this was a mistake. The utility failed on the Intel SSD necessitating a reboot after running for six hours. After the reboot, it turns out that the utility has set a hard drive password on the disk (there was not one before). As I have no way to know what password it has set, I am effectively locked out of my drive and it's a brick to all intents and purposes.


Does anyone (Lenovo in particular) know what password is set during the running of the Secure Erase functionality of the latest BIOS? My only alternative is to find out if there is a default master password from Intel. Since in principle, this should be blank, I believe that I am scuppered unless someone in Lenovo can tell me what password they set using the utility.

 

Thanks in advance.

andyP
Posts: 9,295
Topics: 161
Kudos: 712
Solutions: 636
Registered: ‎11-27-2007
Location: Bonnie Scotland
0

Re: X301 Secure Erase with new BIOS

wibbler, welcome to the forum,

 

there are no default passwords which are set by Lenovo. Which buttons are you pressing at startup which require a password?

 

Excerpt from the forum rules,

 

No posts shall include instructions or directions intended to subvert security measures, including passwords, locking mechanisms, fingerprint scans, etc, nor shall any posts provide descriptions to the location of, nor direct links to content related to these topics.

Andy  

______________________________________


Please remember to come back and mark the post that you feel solved your question as the solution, it earns the member + points

Did you find a post helpfull? You can thank the member by clicking on the star to the left awarding them Kudos

Please add your type, model number and OS to your signature, it helps to help you.

Forum Search Option

T430 2347-G7U W8 x64, Yoga 10 HD+, Tablet 1838-2BG, T61p 6460-67G W7 x64, T43p 2668-G2G XP, T23 2647-9LG XP, plus a few more.

FYI Unsolicited Personal Messages will be ignored.

de.gif  Deutsche Community   es.gif  Comunidad en Español  uk.gif  English Community ru.gif Русскоязычное Сообщество

PepperonI blog 

Blue Screen Again
wibbler
Posts: 4
Registered: ‎07-16-2010
Location: UK
0

Re: X301 Secure Erase with new BIOS

Hi Andy,

 

From the instructions at http://www-307.ibm.com/pc/support/site.wss/document.do?sitestyle=lenovo&lndocid=MIGR-68369:

 

  1. Turn off the computer.
  2. Turn on the computer.
  3. While the "To interrupt normal startup, press the blue ThinkVantage button" message is displayed at the lower-left area of the screen, press the F1 key. The BIOS Setup Utility menu will be displayed. If a password prompt appears, type the correct password.
  4. Select the Security menu of the BIOS Setup Utility menu.
  5. Select the Solid State Drive menu. The following message is displayed. Erase the Solid State Drive in the HDD bay [Enter]
  6. Press Enter key.
    Hitting Enter key makes showing next caution message and confirmation.
  7. Yes confirmation shows next confirmation message.
  8. If a harddisk password was set, a password prompt appears. Type the correct password.
  9. Further process will start after entering the harddisk password.
  10. Press F3 key several times to exit the BIOS Setup Utility.

 

As I did not have a HDD password set, I did not see step 9.

 

The utility is intended to perform a secure erase of a SSD using the ATA command set. In order to achieve this, it must first set a password on the drive (which is why it requires the user tell it the pwd if none has been set - see the end of this post for detailed documentation of this requirement).

 

In normal operation, the password would be cleared at completion of the operation. Because the operation failed however, the password is currently still there. Since I do not know what it is, I have been locked out of the (very expensive) drive.

 

In other tools which perform a secure erase (such as HDDERASE.EXE), the password which is set is documented for situations like this. This is not a security issue, rather it is one of following the correct process as laid down by the ATA standard.

 

It may well be that Lenovo has used a randomly generated password, in which case they have bricked my drive. If not, and a 'default' password is in use, then there is a means to recover the drive if they would document it. Since this is not a security issue, it really shouldn't be a problem. Furthermore, since the password was set without my consent, the security issue is mine since the utility has effectively executed a denial of service on me.

 

See here for details of the ATA secure erase protocols to understand how the password is used:

 

https://ata.wiki.kernel.org/index.php/ATA_Secure_Erase

 

The relevant section which explains why the Lenovo utility does this is:

 

"To successfully issue an ATA Security Erase command you need to first set a user password."

 

This is what the utility has done and by not subsequently removing it, has denied me access to my drive.

 

Cheers.

 

 

 

 

 

community supermod
erik
Posts: 5,038
Registered: ‎11-23-2007
Location: United States
0

Re: X301 Secure Erase with new BIOS


wibbler wrote:

 

The utility failed on the Intel SSD necessitating a reboot after running for six hours.


did you induce the reboot or was it automatically rebooted after showing a failure message?   if you didn't let the utility finish then it wouldn't have had the opportunity to remove the password.   as i understand it the password is randomly generated during the process.

ThinkStation C20Microsoft MVP
ThinkPad X1C · X220 ULV · X60T SXGA+ · s30 · 600

community supermod
erik
Posts: 5,038
Registered: ‎11-23-2007
Location: United States
0

Re: X301 Secure Erase with new BIOS

wibbler - can you post the exact model, build date, and firmware revision of your SSD?   thanks.

ThinkStation C20Microsoft MVP
ThinkPad X1C · X220 ULV · X60T SXGA+ · s30 · 600

Blue Screen Again
wibbler
Posts: 4
Registered: ‎07-16-2010
Location: UK
0

Re: X301 Secure Erase with new BIOS

Hi there,

 

Apologies for disappearing for a while, I've been travelling back from holiday (yes - I rebuild laptops while on holiday). 

 

I don't have the drive with me at work today but I'll post the model, build date and firmware (stock) when I get home tonight.

 

Cheers.

Blue Screen Again
wibbler
Posts: 4
Registered: ‎07-16-2010
Location: UK
0

Re: X301 Secure Erase with new BIOS

[ Edited ]

Drive details:

 

Model: SSDSA1MH080G1Gn 1.8"

SN: CVEM8445xxxxxxxxxx

FW: 8610 (I believe the drive is stock as I did not upgrade it. This is the version on the label)

 

There is no build date on the drive itself.

 

Cheers

 

 

Moderator Note; s/n edited for members own protection

 

Retired Employee
JameZ
Posts: 3,110
Registered: ‎07-11-2010
Location: Malaysia
0

Re: X301 Secure Erase with new BIOS

Hi All,

 

An official tip has been released regarding this issue. Please refer to the following link.

 

//JameZ

Check out the Community Knowledge Base for hints and tips.


Did someone help you today? Press the star on the left to thank them with a Kudo!

If you find a post helpful and it answers your question, please mark it as an "Accepted Solution"!




W520 | 4176-38U | i7 - 2720QM | Quardo 1000M | 8GB RAM | 60GB OCZ Agility 3