Unsolved

1 Rookie

 • 

11 Posts

4604

December 21st, 2022 18:00

Disable Dell Security Manager Password Prompt With Bitlocker Hardware Encryption eDrive

My Dell Precision 5560 is setup with a Samsung 980 Pro with eDrive IEEE1667 SED hardware Bitlocker encryption, a subset of the TCG Opal standard. Everything works great and there is no performance loss as it does hardware encryption.

I am aware of the potential security risks associated with using hardware encryption. Security researchers did not find fault with an earlier Samsung 840/850 Evo when used in TCG Opal mode.

Source: https://www.ru.nl/publish/pages/909282/draft-paper.pdf

The one snag is that the laptop detects that the drive is SED enabled and shows a Dell Security Manager password prompt at every reboot. It does not actually understand the encryption standard being used and entering a password will not work. It also does not care if Bitlocker is temporarily suspended or not. One must hit Cancel, Esc, or let it timeout after about 10 minutes. After which the laptop will proceed to load the Bitlocker PBA and allow the user to successfully enter the password.

This makes running the laptop in headless mode a headache as anytime it restarts for updates even with Bitlocker suspended it will take at least 10 minutes to timeout at reboot.

How does one disable this "feature" (bug)? If it cannot be disabled, then can the timeout be reduced to 30s?

 

DSM Password Prompt On BootDSM Password Prompt On BootHitting Esc Makes DSM Go AwayHitting Esc Makes DSM Go AwayBitlocker PBA Prompt Appears AfterwardsBitlocker PBA Prompt Appears Afterwards

 

 

7 Posts

December 22nd, 2023 02:58

Like almost all annoying Dell UEFI bugs, this will probably never be fixed. Sadly the two options are to either ignore it or sell and buy an Elitebook or Thinkpad. 

1 Rookie

 • 

8 Posts

March 6th, 2024 16:17

Just installed two Samsung 990 PROs in my XPS 17 9730 and utilized hardware OPAL encryption, only to discover this bug. Would have stuck with software had I known.

Dell dissapoints yet again. 

1 Rookie

 • 

37 Posts

March 18th, 2024 22:18

@BrendonSF​ I compared Samsung 990 PRO SED with software encryption (accelerated by AES in Intel 13900H). See the results on the picture below - much slower random read/write plus much higher Intel CPU power usage. Another way to say, SED is much faster and more energy efficient in daily usage. It is no surprise that Apple implemented SED with T2 chip for their storage. But Dell cares not.

https://www.reddit.com/r/Dell/comments/1bi49nc/dell_xps_9730_comparison_of_ssd_speed_with/

(edited)

1 Rookie

 • 

2 Posts

May 6th, 2024 00:03

I have this same issue, patiently awaiting a fix for the last 5 months. I'm going to open a pro support ticket to see if that helps, we're a higher volume customer.... 

1 Rookie

 • 

1 Message

September 8th, 2024 00:06

Continues to be a problem even on the new XPS 16 9640.   I can get hardware encryption enabled on the Samsung 990 but this prompt continues to be an issue. @DELL-Cares please provide a fix. 

1 Rookie

 • 

37 Posts

September 13th, 2024 17:56

@johncampionjr​ , don't hope for it, Dell's ignorance was proven in many cases, not just this. Unless there is a financial damage caused by returns with this problem stated as a reason, they won't fix it. This has been unresolved for many years, why do you think they would fix it in XPS 16 9640. And the problem is not just the lack of the fix but the refusal to provide a detailed response on why this has not been fixed and if this is going to be fixed is the current century.

Interestingly, there is an article published by Dell describing SED vulnerabilities. And while Apple has been using successfully hardware encryption for performance and energy efficiency, Microsoft has also been ignorant using their software BitLocker by default and not trying to encourage hardware encryption for those devices that are unaffected by these vulnerabilities.

This is called "Business Incompetence" - unless planes start falling from the sky and the firm goes bust, incompetent and corrupt managers keep running the company.

https://www.dell.com/support/kbdoc/en-us/000130689/self-encrypting-drives-vulnerabilities-cve-2018-12037-and-cve-2018-12038-mitigation-steps-for-dell-encryption-products

1 Rookie

 • 

37 Posts

September 14th, 2024 22:47

@johncampionjr​ DELL-DoesntCare only deletes comments that show Dell's nature

1 Rookie

 • 

7 Posts

October 1st, 2024 13:33

Hello,

Just bought an Inspiron 14 5440, 7 days ago, replaced the SSD with a Samsung 990 Pro, activated Bitlocker hrdware encryption, and... get the same issue !

If i desactivate bitlocker, it didn't ask for ssd password, if i activate bitlocker, it ask for ssd password.

But i can click cancel, and it continues booting normally, so clearly, this password is not needed... and for me it's a Bios bug.

It doesn't seems to be the bitlocker key, just a password nobody have (because it should not ask for password).

So i would say, it's just really annoying to have to click cancel on start (especially because it's a computer for my wife, non it-specialist).

Seems this issue is long time not solved, i have no chance to get it fixed.

So, it will probably be my last Dell, since other manufacturer seems to be able to bypass this message :(

So bad, i loved my Dell products.

1 Rookie

 • 

37 Posts

October 18th, 2024 22:30

@EricArnould​, it's been 5 years or even more since this problem was first discovered/reported. Dell is very well aware of this bug and the cause of it, but has no intention to fix it. The only thing you can do is publish the details on other forums and social media for potential customers to be aware of the terrible product support and to consider this when choosing new product.

1 Rookie

 • 

7 Posts

December 31st, 2024 14:42

Same problem here. My laptop is Precision 5570 with Samsung SSD 990 Pro.

1 Rookie

 • 

8 Posts

December 31st, 2024 15:49

I went back and forth with a Dell senior tech regarding the issue in March of 2024. After a fair bit of communication, this was their answer:

Internal team recommend to: To turn off Opal encryption and use drive encryption option provided by default windows to test. 

As Opal is 3rd party encryption software it might not be working as suggested with this system. 
So in summary, their response is that it doesn't work. Go fish. 

(edited)

2 Intern

 • 

125 Posts

December 31st, 2024 15:59

@BrendonSF​ Sad fact is, it's an easy fix if they could be arsed to support their products.

1 Rookie

 • 

37 Posts

December 31st, 2024 16:34

@BrendonSF​ , their response it total BS. You can easily consider this as a refusal to provide support. This has nothing to do with 3rd party encryption software. Microsoft BitLocker eDrive is a part of Windows 11 and it directly uses hardware encryption if SSD supports that. TCG Opal is a security standard.

1 Rookie

 • 

8 Posts

December 31st, 2024 17:36

@cheerful_man I completely agree. Unfortunately, it appears that Dell does not.

I just received an XPS 8960 desktop PC. Going to do the same thing; hardware encryption with a 990 Pro. Will be interesting to see if it exhibits the same issue.

1 Rookie

 • 

8 Posts

January 4th, 2025 23:11

Confirmed with my new XPS 9860 desktop (2024 edition PC) that it does NOT have this issue. I've got the same hard drive (990 Pro) and enabled hardware encryption via the exact same methodology. 

So yeah, this is a bug, even if Dell refuses to acknowledge it. 

No Events found!

Top