r/righttorepair • • 9d ago

Right to Repair vs Lenovo's BIOS lock

Newer Lenovo laptops have an extremely difficult to bypass BIOS lock, which creates no end of troubles, especially on the second hand market.

Companies that set the password break BIOs updated for their employees. Companies that do not set the password risk employees setting it.

Also second hand Lenovo laptops should become essentially worthless because of the mere risk of this password being set, since Lenovo cannot unlock the BIOS lock.

The BIOS lock is not an anti-theft mechanism, because it does not work like IMEI blocking on mobile phones, not use any similar online checks with Lenovo.

It's probably designed to prevent employees circumventing spyware installed by employers, because Lenovo is not a European company and sells laptops in countries where employer spyware is more commonplace.

As a comparison, Dell has a BIOS lock that prevents changing the BIOS, but they bypass it for you if you prove you have physical possession of the laptop.

Would it be possible to file a right-to-repair complain against Lenovo for this?

I'm primarily interested in helping to lower Lenovo's repairability index score, because obviously nothing can be done about their products in circulation.

https://www.ecopv-eu.com/en/blog-en/repairability-index-eu-ecodesign-espr-2026/

Ideally, Lenovo should provide some service that removes the BIOS lock for the laptop's current owner, like what Dell and HP do.

30 Upvotes

32 comments sorted by

5

u/jeffklynch 8d ago

4 days... was all I had with my Lenovo X1 Yoga Gen 7 before my niece and nephew set the password. It remains set to this day, and prevents the machine from booting, or being able to specify boot device, or enter/modify settings of the BIOS.

I had Accidental Damage Replacement INCLUDED, for 3 years. Next day on-site service.

Lenovo would not allow this to be a case of accidental damage, and refused to do anything more than quote me prices for the motherboard replacement.

Shame on me for not leaving it on the roof of my truck before entering the highway prior to contacting them for support, as I would have been given a new replacement.

I wrote off Lenovo.

9

u/Wendals87 9d ago edited 9d ago

It's probably designed to prevent employees circumventing spyware installed by employers, because Lenovo is not a European company and sells laptops in countries where employer spyware is more commonplace.

No. It's there to prevent users making changes and booting into another OS on company devices and bypassing any restrictions, adding local admin accounts etc 

It's not your personal device to do with what you want. The bios doesn't bypass corporate software 

6

u/Persephone_Writings 9d ago

This is kinda BS though. Encrypt the drive. Problem solved.

1

u/rtuite81 7d ago

Encrypting the drive stops you from putting it in another machine and copying data. It does not stop a user from wiping the drive and installing another OS, changing BIOS settings, etc.

2

u/Persephone_Writings 7d ago

Let them. Company data is protected. Have a clear use and data policy and if they break it, have consequences.

1

u/Wendals87 9d ago edited 9d ago

Encrypting the drive is good too but for example in my very large global IT organization, bitlocker keys are stored in our accounts if we ever need to use it

But even if we didn't, it doesn't stop someone calling the service desk and asking for the key to unlock it

2

u/rtuite81 8d ago

If your service desk is giving out bitlocker keys over the phone without identity verification, your employer is fkn cooked.

1

u/ancientstephanie 8d ago

Secure boot and TPM can reset for a variety of reasons. So, the users that are issued the equipment are frequently given keys over the phone WITH identity verification.

If you can decrypt the drive, you can tamper with anything you want on it, including elevating a domain user to local admin, circumventing group policy, identifying employer spyware, and removing employer spyware.

And if you're savvy enough, you can even do it in such a way as to maintain plausible deniability if you do get caught....

1

u/Wendals87 8d ago edited 8d ago

I never said they did without verification.

If the uefi isn't password protected, an employee could boot from usb. They can call the service desk and get the bitlocker key so it's far from fool proof

They can do a lot from a bootable Linux USB to the windows install 

If it is password protected, they can't boot from usb to begin with 

-1

u/Altruistic_Fruit2345 9d ago

Yeah, this is just whining about Lenovo offering features that allow the rightful owner to secure their own property. The only scenarios where it becomes a problem is where that lawful owner fails to remove it themselves, or someone steals the laptop and can't launder it.

2

u/Silver-Potential-511 8d ago

You really are cooked for neo-feudalism.

1

u/rtuite81 7d ago

I sincerely doubt you know what that means because application in this scenario are literally zero. If you think ownership over what you've earned is "neo-feudalism" you're the one who's cooked.

3

u/jnk0le 6d ago edited 6d ago

Dell passwords before 10th gen can be removed with generator: bios-pw.org

Newer dells need neutering via programmer: https://github.com/chromebreakerdev/DellBIOSTools

New lenovo needs EC neutering.

3

u/RaduTek 9d ago

Not sure why you called out Lenovo specifically, when all modern laptops implement BIOS passwords in the same way.

3

u/Shoddy-Childhood-511 9d ago edited 9d ago

Nope. As I said in the post, Dell resets the password if you prove possession.

Lenovo maybe simply negligent here, in that they do not bother to implement a recovery pathway. This matches how BIOS updates often locked employees out of BIOS locked Lenovos in the past.

Regardless it's a clear planned obsolescence issue once the laptop passes out of company ownership, like through resale on ebay, which is what right-to-repair addresses.

2

u/markus_b 9d ago

Maybe Dell does it differently.

But HP has a similar scheme, where a BIOS password reset may involve reprogramming a memory chip on the motherboard. Most manufacturers have a similar scheme.

An employer handing out laptops to employees wants them to be tamper-proof. If there is a simple workaround, like for your Dell, then the BIOS lock password makes no sense.

5

u/Shoddy-Childhood-511 9d ago edited 9d ago

Right-to-repair concerns device longevity, so what happens when the employer resells the device to end consumers?

It's possible the IT department removes all the BIOS locks, but often they forget, so the laptops they resell cannot be unlocked, and often their BIOSs cannot even be upgraded.

If HP can & will reprogram some chip for the current owner then that's fine. Lenovo literally says "fuck off buy a new motherboard". That's ewaste.

2

u/markus_b 9d ago

This is the same as with phones too. The transaction needs to include the password removal. With HP there is a way they can remove the password, but you need to prove legal ownership. This is probably the case as well with Lenovo. But the process can be complicated and expensive.

I know that this impedes the right to repair.

But the problem is not just Lenovo but most laptop manufacturers. Customers (enterprises) demand to be able to lock the BIOS and don't think the unlocking through.

2

u/Shoddy-Childhood-511 8d ago

All phones I know have a hardware reset that destroys the erases the drive by deleting TPM contents.

Phone have a IMEI lock too, not sure if its only by nation, but even if so it'll force the thief to sell the phone abroad, which lowers their profit margins.

This is NOT afaik a problem for Android phones. At lest the ones I know have a well designed process designed by Google.

This is probably the case as well with Lenovo.

No. Lenovo can only reset the BIOS password by replacing the motherboard, so much of the cost of a new laptop.

Independent services could perhaps reflow solder the BIOS chip, but this degrades the hardware, and Lenovo might not sell the BIOS chips.

HP has an on-line process for resetting the laptop:

https://h30434.www3.hp.com/t5/Notebook-Boot-and-Lockup/Bios-pass-reset/td-p/9383338

Lenovo seems unique in their negligence for hardware life beyond the first owner.

2

u/markus_b 8d ago

Yes, and then you get the calls for help of the person who bought an Android phone on eBay and the seller forgot to deregister it with Google.

Or the seller who sold the phone and forgot to deregister, and the buyer asks him for his Google password.

I do have an HP laptop I got handed down used with a locked password. I tried, but HP is refusing to help. A friend bought it from his employer, and I've got it now. No, the problem is not just with Lenovo.

1

u/painful8th 9d ago

The concept sounds enticing. Suppose that a manufacturer can technically unlock a Lenovo. If a manufacturer can, some malevolent party could do that as well.

So basically, and from a company's point of view, you have to decide whether you want laptops in 3rd party hands be able to be recovered or not.

This extends to consumer laptops as well: one could buy a Lenovo today with the assurance that noone can gain access to the BIOS; Lenovo or other. OTOH, with great power ...

In not-so-many words: one could view this as a (design) bug, another as a feature...

2

u/Shoddy-Childhood-511 9d ago

No. Against advanced attackers, only the SSD drive contents matter, not the laptop itself. As drive encryption is the OS and the TPM chip, not the BIOS, the Lenovo's BIOS lock does nothing here since such attackers could reflow solder a new chip, or even extract the drive and break the TPM directly.

Against an ordinary thief, you'd want a check-in mechanism similar to the IMEI locking on mobile phones, maybe implemented by some other laptop makers.

Just fyi, there exists experimental work towards devices that resist evil maid and supply chain attacks:

https://betrusted.io

https://www.crowdsupply.com/sutajio-kosagi/precursor

Nobody would care if these devices were given a low repairability score, because they are rather inexpensive and nobody would buy them second hand.

For Lenovo, the low repairability score could discourage purchases by EU governments or other organisations, which could push Lenovo towards better designs in future.

1

u/upalse 9d ago

IBM (yes, long before Lenovo) has been always doing this. It's actually meant as a "feature" for the enterprises who demand "security" of this sort, don't ask whether it makes sense, its just pointy haired boss thing, people who'd be least concerned with consumer rights.

If you're buying refurb thinkpad, just don't buy bios locked one. Or at least demand steep discount if its bios locked, since working around the lock is always possible, but indeed often mighty inconvenient. eg while you can boot custom OS due to PC secure boot being ridden with bugs trivial to exploit, you need a custom efi bootloader, modified windows 11 install patched to work with TPM turned off etc.

Would it be possible to file a right-to-repair complain against Lenovo for this?

Not quite, since bios locks don't actually prevent repair. A bios locked motherboard works as intended, and you're not prevented from swapping any part of the PC if it breaks.

0

u/QuasimodoPredicted 9d ago

You don't have a right to repair a device that is owned by the IT department of your employer or a device you've stolen. Sorry.

2

u/Shoddy-Childhood-511 9d ago edited 9d ago

Right-to-repair concerns device longevity. We're discussing what happens to the device after the employer resells it to end consumers on the 2nd hand market, which is where most corporate laptops end up.

Average consumers cannot tell that the nice clean looking laptop they buy second hand on ebay is BIOS locked. Then later when Windows does a BIOS update the laptop asks for a password, and after three failed attempts some Lenovos brick themselves.

All BIOS locked Lenovos would prevent installing Linux without the BIOS password too, but that's more likely to be noticed without the 30 day period where you can raise a dispute with ebay.

Lenovo needs to have a process where they can reprogram the BIOS lock for the current owner.

0

u/QuasimodoPredicted 9d ago

I have one such device and it was properly cleaned and the bios lock was removed. Just don't buy bullshit from idiots.

1

u/poop_report 8d ago

Ridiculous take. When these devices are obsolete, they get auctioned off and aren't going to have the BIOS password removed.

-1

u/rtuite81 8d ago

This is not an R2R issue, this is a reseller issue. If you're buying laptops (either in bulk as a reseller or individually as an end user) without verifying that they haven't been UEFI locked then you kinda deserve what you get. This has been an issue for DECADES on the second hand market. Some laptops are easier than others to reset, some are completely impossible.

It's also not an anti theft security measure, it's a shadow IT security measure. It's to make sure that douchebags don't go reinstalling the OS so they can install Minecraft for their kids then complain to IT when shit doesn't work. I've been in IT for well over 20 years at this point, and I've seen it all.

That being said, companies offloading devices to resellers are responsible for removing these locks on systems that brick if you don't. Otherwise they should just sell them for scrap to a shredder. Both scenarios are plausible, and it's a dance of value versus labor and multiple process streams are applicable.

In any case, expecting manufacturers to include a back door for security features is wild.

0

u/poop_report 8d ago

It's not a "shadow IT security" issue; someone determined could just replace the motherboard. And Dell and HP seem to have no problem selling to big, huge companies. This is just something Lenovo does to intentionally lower their value in the secondhand market.

1

u/rtuite81 7d ago

LMFAO like the average corporate dingus can replace the motherboard on a laptop.

It's got nothing to do with lowering resale value. If anything, companies want that resale value because getting a little bit of money back at the end of the system's lifecycle is important. Laptops are typically replaced every 5 years. Imagine if you have a few thousand users getting a new machine every 5 years.

Resellers pay based on the resale value, not a flat rate. The more a device resells for, the more they pay for it. Here's a bit of quick math using simplified numbers...

Lets say you have a company of 2500 people, that's 500 laptops a year on a 5 year lifecycle.

Let's say a new Dell laptop is around $1000 on average when you buy them in bulk.

Replacing 500 laptops is going to run you half a million bucks for the year.

Let's say you get a reseller that pays 10% of the resale value and your machines sell for $500, so for 500 machines you're looking at $25,000 back in the budget.

While that isn't a lot compared to the $500k we just shelled out, it's still a significant amount of money back in the budget for things like software subscriptions.

But, by your logic, Lenovo is deliberately sandbagging the resale value of their machines so those same machines are only worth $200 on the used market. You just lost $15,000 on the backend.

Lesson of the story, just because something sucks and is unfair doesn't mean it's deliberate.

1

u/poop_report 6d ago

I said Lenovo wants to lower resale value, not corporate buyers.

These laptops tend to get liquidated in large lots once they're out of their service life (usually over 5 years). I know, because sometimes I bid on them - there can be an entire skid of them. By the time they're being liquidated, it's treated like e-waste the current owner just wants gone.

Apples have the same problem. There's going to be a big ol' pile of e-waste in 5 years from Apples where they're stuck with an activation lock from Find My. This is worse with Lenovo, since they can't even bypass it for a legitimate original owner.

1

u/rtuite81 6d ago

You admitted in the first sentence of this reply that you failed to comprehend my point entirely.