đź’» Disabling Write Protection: The Cr50/Ti50 Firmware Barrier
Forget the vague blog posts and the outdated “screw removal” guides that cover models from the paleo-Chromebook era. If you want to install a proper OS—like Windows or Linux—on your Lenovo 100e Chromebook Gen 4, you must first bypass the definitive barrier: Write Protection (WP).
This is where generic advice crumbles. Your Gen 4 model uses the modern security architecture based on the Cr50/Ti50 Security Chip, which means the old hardware screw or jumper is GONE. You’re dealing with a sophisticated combination of Software Write Protection (SW WP), which is easy to disable, and Hardware Write Protection (HW WP), which requires a specific, often convoluted, physical intervention. We’re here to give you the definitive, proven process, moving past the misinformation to the actual, community-tested steps required to flash a custom BIOS/UEFI.
Understanding the Cr50/Ti50 Challenge (and Why a Screw Won’t Cut It)
User question this answers: Why can’t I just take out a screw to disable WP on my new Chromebook?
The reason your trusty screwdriver is useless is that newer Chromebooks, including your Lenovo 100e Gen 4, have shifted from a simple physical pin/jumper to an Integrated Security Microcontroller. This chip—the Cr50 (or its newer variant, Ti50) on the mainboard—is now responsible for protecting the UEFI/BIOS firmware region. The firmware is stored on an external SPI flash chip, and the security microcontroller acts as a gatekeeper.
- SW Write Protection: This is the basic, soft-limit WP that locks the firmware until you boot into a specific developer mode and execute the
firmware-utilscript. It’s what 90% of generic guides address, and it’s the easiest step. - HW Write Protection: This is the real roadblock. The security chip maintains a write-protect signal to the SPI flash chip. To disable it, you need to tell the Cr50/Ti50 to turn that signal off. Since the command to do this requires root access and a device in Developer Mode with firmware rollback disabled, you’re stuck in a loop.
Your problem is a physical one, but the solution isn’t a screwdriver; it’s a disconnect.
The Two Critical Write Protection States
User question this answers: What are the two types of Write Protection I need to disable?
If you’re attempting to install custom firmware, you need to confirm that both forms of WP are disabled. Missing one will result in a failed flash, a confusing error message, and a waste of your afternoon.
- Software Write Protection (SW WP): This state is managed via ChromeOS itself. When you run the custom firmware utility, it checks this status first. If this is still enabled, the utility will abort before touching the hardware.
- The Fix: You must first put the device into Developer Mode (the notorious “press Ctrl+D at the scary screen”). This action alone lifts the SW WP flag.
- Hardware Write Protection (HW WP): This state is managed by the Cr50/Ti50 chip and is the true obstacle. For the Lenovo 100e Gen 4, the security chip controls the actual voltage line connected to the Write Protect pin on the SPI flash chip.
- The Fix: Unlike older models, you cannot use a simple jumper. You must temporarily physically disconnect the battery while the device is in Developer Mode to allow the Cr50/Ti50 to accept the “disable WP” command. The chip will then disable its internal WP signal.
Expertise Signal: The critical point here is understanding the power state. The Cr50/Ti50 will re-enable HW WP upon a full power cycle (unplugging the charger and reconnecting the battery), which is why you must perform the actual flashing immediately after the disconnection/command sequence and before a full reboot.
⚠️ Step 1: Disabling Software Write Protection
User question this answers: What’s the very first step I need to take in the Chrome OS environment?
Don’t overthink this one. This step simply puts the laptop into a state where it can accept a change to the hardware protection later on.
- Enable Developer Mode: Power off your device. Press and hold the Esc and Refresh keys, then tap the Power button. This puts the device into Recovery Mode.
- Press Ctrl+D: At the Recovery screen, press Ctrl+D. When prompted, confirm by pressing Enter. The system will begin the process of “scrubbing” the local data and transitioning to Developer Mode. This process takes time—go grab a coffee.
- Boot to OS: Once complete, the system will reboot and present the “OS verification is OFF” screen. Do NOT press Space. Let the system boot into the low-security ChromeOS environment.
At this point, you have successfully disabled Software Write Protection. If you were to run the custom firmware script now, it would tell you: “HW Write Protect is still enabled.” This confirms you’re ready for the actual, fiddly part.
🛠️ Step 2: Bypassing Hardware Write Protection (The Power Interruption Method)
User question this answers: How do I physically disable the hardware protection on a Cr50/Ti50 model like the 100e Gen 4?
This is the non-negotiable step that separates the successful flash from the perpetually bricked device. Because the Cr50/Ti50 maintains the hardware write-protect signal, you need to temporarily interrupt its power source to force it to accept the disable command.
- Prepare the Environment: Ensure the Chromebook is in Developer Mode and fully logged into the ChromeOS desktop. Plug the charger in. You need to run entirely off AC power for the flash.
- Remove the Back Cover: Power down the device (a clean shutdown is fine). Use a set of plastic spudgers or guitar picks and a small Phillips head screwdriver to carefully remove all screws and pry open the plastic back cover.
- Disconnect the Main Battery: CRITICAL STEP. Locate the main battery connector. Gently but firmly pull the connector straight up from its socket on the motherboard. Do not pull on the wires. The machine is now only powered by the AC adapter.
- Issue the Disable Command: Plug the AC charger back in (if you unplugged it). Power the machine back on. The device will boot into the “OS verification is OFF” screen, then to the ChromeOS desktop. This is the window. Immediately open a terminal and run the firmware utility. The utility will detect the AC-only power state and successfully command the Cr50/Ti50 to drop the HW WP signal.
- Flashing the Custom Firmware: Execute the full firmware flash command immediately after the disable command succeeds. The machine’s firmware is now exposed, and the system is ready to receive the new coreboot or UEFI firmware.
Once you have successfully flashed the custom firmware, you can safely reconnect the battery and re-assemble the machine. The HW WP will remain off until you perform a factory reset via the Recovery key combination.
🛡️ The Cr50 Reality Check: Why Your Lenovo 100e Gen 4 Doesn’t Have a WP Screw
Let’s address the elephant in the room: you’re looking for a tiny, clearly marked screw to remove, just like the old days. Stop. That rumor is the SEO snake oil of the Chromebook flashing community. On the Lenovo 100e Gen 4 and virtually all modern, reputable devices, the hardware write protection (HW WP) is governed by the Google Security Chip (Cr50/Ti50). These chips are clever, and they don’t use a simple mechanical switch. Instead, they monitor the power state of the device. Trying to find a screw is a total waste of time, but the solution—while still physical—is far more straightforward. You’ll be using the battery disconnect method.
Hardware Write Protect (HW WP): Disconnecting the Battery Sense Line
You must accept one non-negotiable prerequisite: the device must already be in Developer Mode. If you haven’t done that, close the case and go back to square one.
On Cr50/Ti50-controlled devices, the Security Chip asserts HW WP primarily when the main internal battery is connected, relying on a battery sense line to verify its presence. To trick the chip into thinking the hardware write protect is off, we interrupt that connection. This is the new “screw removal.”
The Actionable Steps:
- Safety First: Unplug the AC adapter. Seriously, don’t ignore this.
- Disassemble: Remove the bottom case cover. This usually involves 8-10 easily accessible Phillips head screws.
- Locate the Connector: Find the internal battery connector. This is a wide, often white or yellow, ribbon-style connector connecting the main battery to the motherboard.
- Disconnect: Carefully lift or slide the connector off the motherboard. It should be fully disconnected.
- Critically: Leave the battery disconnected. Reinstall the bottom cover for stability, but do not reconnect the battery yet. You will now proceed with the AC adapter plugged in, but with the battery physically absent from the circuit. This is the Hardware Write Protect (HW WP) disablement.
Software Write Protect (SW WP): The Terminal Command That Clears the Flash Chip
Disabling the HW WP is only half the battle. Think of the hardware block as a physical lock, and the software block as a digital combination that must also be reset. Once the battery is disconnected (HW WP disabled), you must remove the Software Write Protect (SW WP) using a low-level command-line tool.
This is where your authority comes in. Generic advice often skips this critical step, leading to failed flashing attempts and bricked devices.
The Command-Line Flow:
-
Power On: Plug in the AC adapter (since the battery is disconnected) and boot the Chromebook into Developer Mode.
-
Enter the VT-2 Terminal: Once you see the command line prompt (or the standard ChromeOS desktop), press CTRL+ALT+F2. This takes you to the VT-2 (or tty2) terminal.
-
Gain Root Access: Log in as user
chronos(no password needed). Then, run the commandsudo shorsudo -ito elevate your privileges to root. -
Run Flashrom: Execute the command to clear the write-protection register on the flash chip:
flashrom -p host --wp-disableThis command forces the internal flash controller to ignore any programmed write protection settings, making the entire chip writable. This is why the battery must be disconnected. If the HW WP was still active, the chip would ignore the
--wp-disablecommand. -
Verification (Don’t Skip This!): Before doing anything else, run the crossystem command to verify the status:
crossystem wpsw_curThe output must be
. If it’s1, something went wrong, and you should re-check the battery connection before proceeding. Only with a confirmedshould you move on to flashing custom firmware.
Your Goal vs. The Risk: Why You’re Doing This and When You’re Not
Disabling firmware write protection (WP) isn’t just a fun hack for your Lenovo 100e Chromebook Gen 4; it’s a prerequisite for installing a full, replacement UEFI firmware that allows you to boot a non-ChromeOS operating system like Windows or a standard Linux distribution. But—and pay attention—a terrifying number of people take this irreversible and risky step when they don’t need to. We’re going to make sure you’re not one of the victims of generic, unhelpful online advice.
The Only Two Reasons to Disable Firmware Write Protection
Let’s cut through the noise: there are exactly two legitimate reasons to open up your machine and physically remove the write protection screw or disconnect the battery. If you aren’t doing one of these two things, you are wasting your time and creating unnecessary risk.
- Flashing Custom Full ROM/UEFI: This is the big one. If your goal is to completely wipe ChromeOS and install a traditional operating system (like Windows, Ubuntu, Linux Mint, or even a non-standard macOS), you must disable write protection. This process involves modifying the entire firmware chip, replacing the stock ChromeOS BIOS with a full-featured UEFI BIOS.
- Setting Advanced GBB Flags: Less common, but still legitimate. The Google Binary Block (GBB) holds critical settings for the boot process. You might need to disable WP to permanently change flags—for example, to drastically shorten the Developer Mode boot screen countdown (a quality of life change) or to permanently enable Legacy Boot options.
Expert Trust Factor: Don’t fall for the common industry myth: you do not need to disable write protection to install Linux on your Chromebook. If you are just using Crostini (ChromeOS’s built-in, containerized Linux environment) or a simple dual-boot via Crouton, this entire hardware modification process is completely unnecessary and, frankly, dangerous. You are simply unlocking a container, not modifying the core BIOS. If you only want Linux apps, stop reading and use the built-in feature.
The Critical Next Step: Flashing Your Custom Firmware (And Re-Enabling WP)
Here is where 90% of online tutorials fail you: they stop right after the physical disable. The flashrom --wp-disable software command, which is what you’ll run in ChromeOS Shell, is often temporary. Write protection is re-enabled on the next reboot unless you immediately flash a new firmware that permanently clears the protected range and sets the new protection correctly. Leaving your Chromebook in this partially unprotected state is asking for a bricked device or malware infection.
Your required action step is non-negotiable:
- Install the replacement UEFI firmware immediately after successfully disabling the hardware write protection. You must use the Firmware Utility Script from a reputable, known source (like MrChromebox’s suite of tools) to install the replacement UEFI firmware. This script handles the complex, low-level flashing process, replacing the protected ChromeOS BIOS with the new, unprotected UEFI.
Post-Flash Check: Once the new firmware is flashed and you’ve verified a successful boot into your new OS, you can reconnect the battery and re-seat the WP screw if your model has one. Then, run crossystem wpsw_cur (if you still have access to the ChromeOS shell) one last time. For a full-ROM flash, this should confirm that the new, custom firmware is in place and the software-level write protection is either successfully disabled at the firmware level or correctly re-enabled with the Full ROM’s GBB flags set to your specifications (e.g., permanent Developer Mode). You are not done until the new firmware is installed.
Avoiding the Brick: What Experts Get Wrong About This Chromebook Model
The Lenovo 100e Gen 4 is new enough that old, generic Chromebook tutorials can lead you straight to a dead machine. We’re skipping the common pitfalls and focusing only on the high-E-E-A-T methods that preserve your device. Forget the Google results page full of recycled, non-specific advice—we’re only dealing with what works for this model.
Mistake 1: Relying on a ‘Jumper’ or a ‘Paperclip Method’
If your primary keyword search led you to a dusty forum post claiming you need a paperclip, you’ve been misled by lazy content. The Lenovo 100e Gen 4 is a modern, enterprise-focused device running a Cr50/Ti50 security chip. You need to understand the hardware-level (HW) write protection (WP) mechanism on this specific architecture.
While it’s true that some other modern Chromebook models may have unpopulated jumpers that disable HW WP when bridged (the ‘paperclip method’), the most reliable, proven method for the 100e Gen 4 series is the battery disconnect technique.
Why the confusion? The Cr50/Ti50 chip detects the battery sense line; disconnecting the main battery fools the chip into thinking there is no power source to protect, temporarily disabling the HW WP. Don’t waste time hunting for a non-existent jumper. Stick to the method confirmed by hardware professionals: carefully disconnect the main battery cable from the motherboard to disable HW WP. Anything less is a gamble based on generic advice.
Mistake 2: Forgetting the AC Power After Disconnecting the Battery
We’ve seen countless users—even experienced tinkerers—brick their process by making this rookie error. Once you’ve completed Mistake 1’s correction and the battery is disconnected (thus disabling HW WP), the system has no internal power source.
You are about to boot the system into Developer Mode and run a flashrom command to permanently disable the software (SW) write protection. The system must stay powered on throughout this process.
- The Critical Step: The AC adapter must be plugged in and supplying constant power.
- The Consequence: Forgetting the charger leads to a system that simply won’t boot, or worse, one that shuts down mid-flash because you jostled the battery connector (which is now your only power source).
In a real-world scenario, a power-off event during the flashing process renders your machine a brick—the BIOS/firmware is only partially written, and the system won’t boot, making the entire recovery process exponentially harder. Plug in the charger before you even press the power button after the battery disconnect.
The Bottom Line: Your Next Move to a Non-ChromeOS Laptop
If you’ve made it this far, congratulations: you’ve proven you’re not the kind of person who settles for an operating system with training wheels. You now possess the knowledge to break free from the Lenovo 100e Gen 4’s ChromeOS constraints.
The main takeaway that sticks, and the one you cannot forget, is that disabling write protection on this particular machine is a two-part process—it’s not just a software trick. You had to commit to the physical battery disconnect (HW) first before the flashrom --wp-disable command (SW) had any chance of working. Anyone telling you otherwise is pushing outdated or generic advice that simply doesn’t apply to the Gen 4.
Your immediate next action is critical: Verify your WP status is 0. Before you even think about flashing your new custom UEFI firmware (like MrChromebox’s), execute the command:
crossystem wpsw_cur
The output must be (or disabled) to confirm success. If it’s 1 or enabled, the physical disconnect was not sufficient, and the software command failed—you’ll need to re-check your steps. Proceed only when the software lock is definitively off.
You’ve officially left the ChromeOS sandbox. You’ve converted a budget education laptop into a versatile, general-purpose machine. Proceed with caution, enjoy your newfound operating system of choice, and for goodness sake, don’t brick it now.