UNSOLVED

ltctech

updated

4 months ago

L

ltctech

2 Intern

11 Posts

5

5119

December 21st, 2022 18:00

Disable Dell Security Manager Password Prompt With Bitlocker Hardware Encryption eDrive

My Dell Precision 5560 is setup with a Samsung 980 Pro with eDrive IEEE1667 SED hardware Bitlocker encryption, a subset of the TCG Opal standard. Everything works great and there is no performance loss as it does hardware encryption.

I am aware of the potential security risks associated with using hardware encryption. Security researchers did not find fault with an earlier Samsung 840/850 Evo when used in TCG Opal mode.

Source: https://www.ru.nl/publish/pages/909282/draft-paper.pdf

The one snag is that the laptop detects that the drive is SED enabled and shows a Dell Security Manager password prompt at every reboot. It does not actually understand the encryption standard being used and entering a password will not work. It also does not care if Bitlocker is temporarily suspended or not. One must hit Cancel, Esc, or let it timeout after about 10 minutes. After which the laptop will proceed to load the Bitlocker PBA and allow the user to successfully enter the password.

This makes running the laptop in headless mode a headache as anytime it restarts for updates even with Bitlocker suspended it will take at least 10 minutes to timeout at reboot.

How does one disable this "feature" (bug)? If it cannot be disabled, then can the timeout be reduced to 30s?

 

DSM Password Prompt On BootDSM Password Prompt On BootHitting Esc Makes DSM Go AwayHitting Esc Makes DSM Go AwayBitlocker PBA Prompt Appears AfterwardsBitlocker PBA Prompt Appears Afterwards

 

 

  • cheerful_man

    2 Intern

    38 Posts

    0

    0

    Posted September 27th, 2023 21:32

    XPS 9730 same problem. @DELL-Cares please let us know if the problem is going to be resolved.

    (edited)

  • cheerful_man

    2 Intern

    38 Posts

    0

    0

    Posted March 18th, 2024 22:18

    @BrendonSF​ I compared Samsung 990 PRO SED with software encryption (accelerated by AES in Intel 13900H). See the results on the picture below - much slower random read/write plus much higher Intel CPU power usage. Another way to say, SED is much faster and more energy efficient in daily usage. It is no surprise that Apple implemented SED with T2 chip for their storage. But Dell cares not.

    https://www.reddit.com/r/Dell/comments/1bi49nc/dell_xps_9730_comparison_of_ssd_speed_with/

    (edited)

  • cheerful_man

    2 Intern

    38 Posts

    0

    0

    Posted September 13th, 2024 17:56

    @johncampionjr​ , don't hope for it, Dell's ignorance was proven in many cases, not just this. Unless there is a financial damage caused by returns with this problem stated as a reason, they won't fix it. This has been unresolved for many years, why do you think they would fix it in XPS 16 9640. And the problem is not just the lack of the fix but the refusal to provide a detailed response on why this has not been fixed and if this is going to be fixed is the current century.

    Interestingly, there is an article published by Dell describing SED vulnerabilities. And while Apple has been using successfully hardware encryption for performance and energy efficiency, Microsoft has also been ignorant using their software BitLocker by default and not trying to encourage hardware encryption for those devices that are unaffected by these vulnerabilities.

    This is called "Business Incompetence" - unless planes start falling from the sky and the firm goes bust, incompetent and corrupt managers keep running the company.

    https://www.dell.com/support/kbdoc/en-us/000130689/self-encrypting-drives-vulnerabilities-cve-2018-12037-and-cve-2018-12038-mitigation-steps-for-dell-encryption-products

  • cheerful_man

    2 Intern

    38 Posts

    0

    0

    Posted September 14th, 2024 22:47

    @johncampionjr​ DELL-DoesntCare only deletes comments that show Dell's nature

  • cheerful_man

    2 Intern

    38 Posts

    0

    0

    Posted October 18th, 2024 22:30

    @EricArnould​, it's been 5 years or even more since this problem was first discovered/reported. Dell is very well aware of this bug and the cause of it, but has no intention to fix it. The only thing you can do is publish the details on other forums and social media for potential customers to be aware of the terrible product support and to consider this when choosing new product.

  • cheerful_man

    2 Intern

    38 Posts

    0

    0

    Posted December 31st, 2024 16:34

    @BrendonSF​ , their response it total BS. You can easily consider this as a refusal to provide support. This has nothing to do with 3rd party encryption software. Microsoft BitLocker eDrive is a part of Windows 11 and it directly uses hardware encryption if SSD supports that. TCG Opal is a security standard.

  • cheerful_man

    2 Intern

    38 Posts

    0

    0

    Posted November 18th, 2025 19:44

    Not worth wasting time on this, erase device erases completely SSD with SED area. Recover does not and cannot start SED, you need to use Samsung Magician for that.

    manage-bde -status

  • Dawidmos

    1 Rookie

    13 Posts

    1

    0

    Posted November 18th, 2025 19:57

    yes, my mistake - sorry 😒 I didn't notice that it's XTA instead of hardware - stupid manage-bde. Still no communication bde with bios (enforced with gpedit.msc enter message has back)

  • EricArnould

    1 Rookie

    9 Posts

    2 Points

    1

    0

    Posted December 1st, 2025 08:23

    Just received my new Alienware AA16250 Laptop.
    Added a Samsung P9100 Pro & a Samsung 990 Pro.

    Didn't find the command to unblock SID in the BIOS first... After updating BIOS, i found it.
    Wipe done from the bios also, always difficult to have magician erase key to boot on :p

    Tried to activate hardware bitlocker, success (as always), but seems to be AES 256 on both !

    On previous try with 990 Pro & another computer, i only got AES 128.

    Benchmark software shows no perf lost (strangely even a little bit better perfs ^^) !

    14 GB/s with hadware AES256 ^^ (and 7GB/s on the 990), and same IOPS even on heavy loads.

    (while software encrypt was dramatic on IOPS)

    Very easy at least to hardware encrypt with latest bios.

    In BIOS, Set Unblock SID, then use wipe disk option (also in BIOS).
    Install Win 11, set gpedit policy to hardware and activate bitlocker ^^

    No need any rufus/win2go :p

    But still the password message on boot (esc+enter).
    Note : The message is displayed for each encrypted drives. So i got to "escape it" 2 times (tried 3 encrypted disks, and needed to do it 3 times).

    Still only 1s task, but still boring @DELL-Cares ;)

  • Greeeatscott

    1 Rookie

    4 Posts

    2 Points

    0

    0

    Posted April 23rd, 2026 09:49

    @EricArnould​ did you ever find a fix for this? I've been dealing with it for a while and is extremely annoying, as the computer doesn't continue to boot after time out it shuts down very annoying for startup I have to sit there and wait to hit cancel and proceed. Makes restarting a pain.