General Computing
ssd thinkpad secure-erase
Updated Wed, 24 Aug 2022 14:58:45 GMT

Secure erase SSD on Lenovo ThinkPad T520 (can't unfreeze SSD, machine reboots on hotplug)


I have a ThinkPad T520 and a Samsung 840 EVO 256GB SSD that I'm trying to secure erase.

I cannot secure erase the drive because I cannot unfreeze the drive because I cannot remove then reinsert the drive without the computer rebooting itself (and re-freezing the drive).

I'm sure the concept of "freezing" SSDs and requiring a power cycle to unfreeze makes sense to the autistic basement-monkeys that thought that one up, but I need to find a way to actually perform this task.

Things I've tried so far:

  • Samsung Magician secure erase USB boot disk. Reboot machine, drive is frozen, program instructs disconnect + reconnect drive without powering off machine. I remove drive from internal bay. I reinsert. Machine reboots on reinsert. Drive is re-frozen.
  • Boot to Linux from USB, hoping it was some OS level driver thing. Similar result.
  • Disable SATA AHCI in BIOS. I don't know why this would have an effect but I was grasping at straws. Similar result.
  • Samsung Magician to secure erase drive via USB enclosure. Secure erase not supported over USB, as expected.
  • I already have the latest BIOS. Lenovo has an old BIOS extension for secure erasing SSDs but it does not support the T520, it only supports older machines.

The reboot on reinsert does not occur when I hotplug a Crucial M4. It only occurs with the Samsung 840 EVO. These are the only two drives I have, so I don't know which one is the exception.

My questions:

  1. Why does the machine reboot when I plug in the Samsung and how can I stop this from happening?
  2. If I can't, is there a less ridiculous way to unfreeze an SSD?
  3. If not, is there some way to secure erase an SSD over USB?
  4. If not, how do I secure erase this drive short of purchasing a new computer?



Solution

I was able to do this. It turns out Lenovo makes a utility specifically for secure erasing drives that is compatible with the T520 (and many other models). It looks like this utility is the more modern replacement for the BIOS extension that is available for older models.

So if you have a ThinkPad newer than circa 2011, check the "Storage" subsection under the drivers/downloads area for your model ThinkPad at the Lenovo web site.

For me, with the T520, it was the adorably Engrish Drive Erase Utility for the Resetting the Cryptographic Key and the Erasing the Solid State Drive.

  1. Download the above ISO (check the supported model list to make sure it is for your ThinkPad first; search for your model on their web site if it isn't).
  2. Burn it to a CD or DVD (or ThumbDrive, use UNetbootin or Rufus - although I have not tried this and have run into issues in the past with Lenovo ISO's that use the Nero Bootloader, dunno about this one though.)
  3. Power off laptop, install the drive you want to erase.
  4. Boot laptop with CD/DVD in. If it doesn't boot automatically hammer on F12 when the machine turns on to display the boot menu and choose the CD-ROM drive from there.
  5. Follow the instructions on the screen for erasing the drive and resetting the key. Takes about 5 minutes tops.
  6. Label and save the disc you just burned, it will come in handy if you have to do this again.
  7. You're all done. Power off machine and remove the drive, then tell all your friends the story. They'll love it. Great conversation starter at parties as well.

The Lenovo utility accomplishes the unfreeze by generating some sort of key you have to write down, then rebooting the machine (presumably doing some magic to power cycle the SATA device without re-freezing it) and asking you for the key again.

Confirmed working with Crucial M4 and Samsung 840 EVO.

Note that you may wish to ensure that you have the latest BIOS update for your PC installed (as well as the latest firmware for your SSD drives). BIOS updates can also be found on the Lenovo site in the section for your model laptop.

I cannot explain why I am able to hotplug the M4 but not the 840. It does not really matter now but I'd still be interested to know just for academic reasons.





Comments (3)

  • +1 – Looks like neither UNetbootin (625) nor Rufus (2.12) can handle this ISO... — Feb 17, 2017 at 07:40  
  • +1 – Still an issue with Rufus 3.17, but I have had success with the free trial of UltraISO — Nov 15, 2021 at 20:33  
  • +0 – Thanks. I'll have to retest and update with a list of working boot image utilities. I'm assuming the landscape has changed in the past 7 years. The other answers here have good additional options, too. — Nov 15, 2021 at 20:51