Unsolved

This post is more than 5 years old

12 Posts

22086

March 12th, 2016 16:00

Setting ATA password on M4500 for secure full disk encryption

I just bought a new Evo 850 mSata drive for my Dell M4500 Laptop. The Evo supports hardware encryption, and I would like to protect it via ATA password (NOT via Bitlocker). Unfortunately, I am facing 3 problems:

#1 The ATA password doesn't allow for special characters. Which is odd, because according to DELL's support article here, the problem has been solved some time ago:

www.dell.com/.../EN

Granted, the article applied to the E-Series, but I own an E6500 as well, upgraded it to the latest A29 firmware and, sure enough, it doesn't accept special characters either. What am I missing?

#2 After setting the SATA controller to AHCI and installing Windows in UEFI mode, the option to set an ATA password is mysteriously GONE from the BIOS (it is only available with Legacy BIOS, or with UEFI + ATA mode). After googling around, I dug up this old thread:

en.community.dell.com/.../19395511

I would hate to believe that that DELL simply "solved" this by removing the entire option from BIOS, rather than fixing the underlying issue - but then again, if that is indeed the case, I'd at least like to know about it so I can move on.

#3 I am one of those who would like to encrypt their data with the purpose of actually keeping others from accessing it. From what I have read, that isn't as easy as it seems, because even after specifying a password for my HDD access, it seems like Dell is still providing various backdoors so my data can be accessed without my password, and these aren't properly documented. Therefore, I would need some sort of walkthrough so I can make sure my data is actually safe.

My concerns include, but are not limited to, the two following issues:
- I read it's possible to override the HDD password with some sort of master password. This leads to the conclusion that the Dell BIOS must somehow know my HDD password and store it somewhere outside of the HDD, because otherwise, it wouldn't be possible to unlock the HD without actually entering the password.
- Dell also seems to offer some kind of way to overcome the HD encryption by contacting Dell support. It seems like this can be turned off by enabling the "Secure Erase" option in BIOS (i.e. disk will be automatically erased if that recovery password is entered), but that still raises the question how the option to fully recover data from an encrypted HD is possible in the first place, when all that should really exist from a security perspective is a one-way hash that is stored on the encrypted drive itself. Details would be highly appreciated!

No Responses!
No Events found!

Top