• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
HP Recommended
ZBook Fury G8

Essentially the same issue described in this thread several years ago. 

 

When using DriveLock on multiple drives, HP's UEFI prompts for a password on every drive, even if the same password is used for all of them, which is unusual and a behavior not found on Dell or Lenovo machines.

 

You might ask, "why not use Automatic DriveLock?". Here's why:

 

According to HP's documentation: When this setting is checked, the BIOS sets a randomly generated user password, sets the master password with the BIOS administrator password, and marks the drive as a member of an Automatic DriveLock group

This is problematic because, in addition to trusting the drive's OPAL implementation, you must now trust HP's UEFI to handle keys in a secure manner as well. Also, should your laptop break, you'll be unable to unlock your drives on a non-HP machine using third-party SED software - even with the BIOS administrator password - because some form of key derivation is apparently involved. I tested this by attempting to unlock the drive using third-party SED software and the cleartext BIOS administrator password, but it was unsuccessful. 

 

I'm not sure whether this is a bug or intended, but I see no reason for the UEFI to prompt for an SED password for every drive if the same password is being used. Also, neither Thinkpads nor Precision devices have this behavior.

 

1 REPLY 1
HP Recommended

After having analyzed how the firmware handles this, it appears that this behavior is consistent across both current and older ZBook generations and is not a bug. I believe implementing password caching to unlock subsequent drives, similar to the functionality found in ThinkPad and Dell devices, would be a significant improvement without compromising security. Maybe a moderator could forward this feedback to the relevant engineering team?

 

Also, when using Automatic DriveUnlock, the BIOS admin and drive user passwords are stored in the BIOS NVRAM. Since the TPM is not involved, this implementation is rather a basic deterrent and is not going to withstand more sophisticated attacks.

† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.
-->