Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.sys.mac.system > #29288 > unrolled thread
| Started by | dcohenspam@talktalk.net (Daniel Cohen) |
|---|---|
| First post | 2012-08-10 19:01 +0100 |
| Last post | 2012-08-14 15:49 +0100 |
| Articles | 20 on this page of 29 — 12 participants |
Back to article view | Back to comp.sys.mac.system
firmware password dcohenspam@talktalk.net (Daniel Cohen) - 2012-08-10 19:01 +0100
Re: firmware password me@home.spamsucks.ca (Király) - 2012-08-10 18:14 +0000
Re: firmware password Michelle Steiner <michelle@michelle.org> - 2012-08-10 11:26 -0700
Re: firmware password Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-10 20:20 +0000
Re: firmware password Michelle Steiner <michelle@michelle.org> - 2012-08-10 13:27 -0700
Re: firmware password nospam <nospam@nospam.invalid> - 2012-08-10 16:37 -0400
Re: firmware password Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-11 03:54 +0000
Re: firmware password Michelle Steiner <michelle@michelle.org> - 2012-08-10 21:03 -0700
Re: firmware password J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-11 06:23 -0400
Re: firmware password Michelle Steiner <michelle@michelle.org> - 2012-08-11 07:39 -0700
Re: firmware password J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-11 15:24 -0400
Re: firmware password Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-11 13:41 -0400
Re: firmware password JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-11 14:12 -0400
Re: firmware password Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-11 18:38 +0000
Re: firmware password nospam <nospam@nospam.invalid> - 2012-08-11 10:57 -0400
Re: firmware password Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-10 14:37 -0400
Re: firmware password me@home.spamsucks.ca (Király) - 2012-08-10 23:46 +0000
Re: firmware password Michael Vilain <vilain@NOspamcop.net> - 2012-08-11 13:21 -0700
Re: firmware password J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-11 06:23 -0400
Re: firmware password nospam <nospam@nospam.invalid> - 2012-08-10 15:11 -0400
Re: firmware password Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-10 20:15 +0000
Re: firmware password dcohenspam@talktalk.net (Daniel Cohen) - 2012-08-11 12:18 +0100
Re: firmware password Ant <ant@zimage.comANT> - 2012-08-11 14:12 -0700
Re: firmware password Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-11 18:39 -0400
Re: firmware password Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-12 02:22 +0000
Re: firmware password billy@MIX.COM - 2012-08-12 03:55 +0000
Re: firmware password dcohenspam@talktalk.net (Daniel Cohen) - 2012-08-12 14:27 +0100
Re: firmware password billy@MIX.COM - 2012-08-14 03:06 +0000
Re: firmware password dcohenspam@talktalk.net (Daniel Cohen) - 2012-08-14 15:49 +0100
Page 1 of 2 [1] 2 Next page →
| From | dcohenspam@talktalk.net (Daniel Cohen) |
|---|---|
| Date | 2012-08-10 19:01 +0100 |
| Subject | firmware password |
| Message-ID | <1komcau.a6j0ko7lmxv8N%dcohenspam@talktalk.net> |
I am considering setting a firmware password on my Mac. Using Montain Lion, if I want to change startup disks using the option key at startup I can do it provided I enter the firmware password. From various discussion forums (it does not seem to be mentioned on Apple's site) I get the impression that other things one might want to do at startup (verbose mode, single-user mode) are not possible at all when a firmware password is set, it isn't a matter of having to enter the password to continue. Am I right in this? If so, what actions are prohibited sompletely and which trquite a password? -- <http://www.decohen.com> The Labyrinth of the Heart: Changed Myths for Changing Lives book and e-book <http://www.decohen.com/labyrinth> Send e-mail to the Reply-To address, not the From address.
[toc] | [next] | [standalone]
| From | me@home.spamsucks.ca (Király) |
|---|---|
| Date | 2012-08-10 18:14 +0000 |
| Message-ID | <k03j1q$4d3$1@dont-email.me> |
| In reply to | #29288 |
Daniel Cohen <dcohenspam@talktalk.net> wrote: > I am considering setting a firmware password on my Mac. > > Using Montain Lion, if I want to change startup disks using the option > key at startup I can do it provided I enter the firmware password. > > From various discussion forums (it does not seem to be mentioned on > Apple's site) I get the impression that other things one might want to > do at startup (verbose mode, single-user mode) are not possible at all > when a firmware password is set, it isn't a matter of having to enter > the password to continue. > > Am I right in this? If so, what actions are prohibited sompletely and > which trquite a password? Setting the firmware password has one useful purpose - preventing users from gaining unauthorized admin access, by preventing them from booting into single user mode, or booting from DVD. It does not, as many seem to believe, make one's data more secure from being stolen. The firmware password is also easy to defeat, by adding or removing a RAM module and then resetting PRAM. So it's rather useless protectionif the intruder has physical access to the machine. A useful scenario is an institutional sysadmin who manages a fleet of laptops, who doesn't want users to have admin access. He can set the firmware password, and then put a label over the RAM hatch that says "break this seal and you're fired/expelled." Beyond that, there are few advantages to setting a firmware password. -- K. Lang may your lum reek.
[toc] | [prev] | [next] | [standalone]
| From | Michelle Steiner <michelle@michelle.org> |
|---|---|
| Date | 2012-08-10 11:26 -0700 |
| Message-ID | <michelle-4DDB32.11265310082012@news.eternal-september.org> |
| In reply to | #29290 |
In article <k03j1q$4d3$1@dont-email.me>, me@home.spamsucks.ca (Király) wrote: > The firmware password is also easy to defeat, by adding or removing a > RAM module and then resetting PRAM. So it's rather useless protectionif > the intruder has physical access to the machine. And not necessary if the intruder doesn't have physical access. -- Tea Party Patriots is to Patriotism as People's Democratic Republic is to Democracy.
[toc] | [prev] | [next] | [standalone]
| From | Lewis <g.kreme@gmail.com.dontsendmecopies> |
|---|---|
| Date | 2012-08-10 20:20 +0000 |
| Message-ID | <slrnk2ar94.voq.g.kreme@mbp55.local> |
| In reply to | #29292 |
In message <michelle-4DDB32.11265310082012@news.eternal-september.org> Michelle Steiner <michelle@michelle.org> wrote: > In article <k03j1q$4d3$1@dont-email.me>, me@home.spamsucks.ca (Király) > wrote: >> The firmware password is also easy to defeat, by adding or removing a >> RAM module and then resetting PRAM. So it's rather useless protectionif >> the intruder has physical access to the machine. > And not necessary if the intruder doesn't have physical access. There are degrees of physical access. You might have access to the machine to plug in a drive or put in a DVD, but not be able to open the machine to remove RAM, for example. It's another layer of security that can be very useful in certain situations. -- Elves are wonderful. They provoke wonder. Elves are marvellous. They cause marvels. Elves are fantastic. They create fantasies. Elves are glamorous. They project glamour. Elves are enchanting. They weave enchantment. Elves are terrific. They beget terror.
[toc] | [prev] | [next] | [standalone]
| From | Michelle Steiner <michelle@michelle.org> |
|---|---|
| Date | 2012-08-10 13:27 -0700 |
| Message-ID | <michelle-750CCD.13274410082012@news.eternal-september.org> |
| In reply to | #29296 |
In article <slrnk2ar94.voq.g.kreme@mbp55.local>, Lewis <g.kreme@gmail.com.dontsendmecopies> wrote: > >> The firmware password is also easy to defeat, by adding or removing a > >> RAM module and then resetting PRAM. So it's rather useless > >> protectionif the intruder has physical access to the machine. > > > And not necessary if the intruder doesn't have physical access. > > There are degrees of physical access. You might have access to the > machine to plug in a drive or put in a DVD, but not be able to open the > machine to remove RAM, for example. Got an example of how that would happen? -- Tea Party Patriots is to Patriotism as People's Democratic Republic is to Democracy.
[toc] | [prev] | [next] | [standalone]
| From | nospam <nospam@nospam.invalid> |
|---|---|
| Date | 2012-08-10 16:37 -0400 |
| Message-ID | <100820121637046897%nospam@nospam.invalid> |
| In reply to | #29297 |
In article <michelle-750CCD.13274410082012@news.eternal-september.org>, Michelle Steiner <michelle@michelle.org> wrote: > > There are degrees of physical access. You might have access to the > > machine to plug in a drive or put in a DVD, but not be able to open the > > machine to remove RAM, for example. > > Got an example of how that would happen? macbook air.
[toc] | [prev] | [next] | [standalone]
| From | Lewis <g.kreme@gmail.com.dontsendmecopies> |
|---|---|
| Date | 2012-08-11 03:54 +0000 |
| Message-ID | <slrnk2blqq.144n.g.kreme@mbp55.local> |
| In reply to | #29297 |
In message <michelle-750CCD.13274410082012@news.eternal-september.org> Michelle Steiner <michelle@michelle.org> wrote: > In article <slrnk2ar94.voq.g.kreme@mbp55.local>, > Lewis <g.kreme@gmail.com.dontsendmecopies> wrote: >> >> The firmware password is also easy to defeat, by adding or removing a >> >> RAM module and then resetting PRAM. So it's rather useless >> >> protectionif the intruder has physical access to the machine. >> >> > And not necessary if the intruder doesn't have physical access. >> >> There are degrees of physical access. You might have access to the >> machine to plug in a drive or put in a DVD, but not be able to open the >> machine to remove RAM, for example. > Got an example of how that would happen? High school computer lab with macbooks that are bolted to a metal plate. MacPros that have a cable lock through the side panel release, just to mention two I've seen. -- He [Vimes]'d never felt really at home with swords, but a cleaver was a different matter. A cleaver had weight. It had purpose. A sword might have a certain nobility about it, unless it was the one belonging for example to Nobby, which relied on rust to hold it together, but what a cleaver had was a tremendous ability to cut things up.
[toc] | [prev] | [next] | [standalone]
| From | Michelle Steiner <michelle@michelle.org> |
|---|---|
| Date | 2012-08-10 21:03 -0700 |
| Message-ID | <michelle-15D0F2.21035810082012@news.eternal-september.org> |
| In reply to | #29308 |
In article <slrnk2blqq.144n.g.kreme@mbp55.local>, Lewis <g.kreme@gmail.com.dontsendmecopies> wrote: > >> >> The firmware password is also easy to defeat, by adding or > >> >> removing a RAM module and then resetting PRAM. So it's rather > >> >> useless protectionif the intruder has physical access to the > >> >> machine. > >> > >> > And not necessary if the intruder doesn't have physical access. > >> > >> There are degrees of physical access. You might have access to the > >> machine to plug in a drive or put in a DVD, but not be able to open > >> the machine to remove RAM, for example. > > > Got an example of how that would happen? > > High school computer lab with macbooks that are bolted to a metal plate. > MacPros that have a cable lock through the side panel release, just to > mention two I've seen. Someone who would want to hack a computer by removing RAM is not going to be stopped by something like that if he's determined enough. -- Tea Party Patriots is to Patriotism as People's Democratic Republic is to Democracy.
[toc] | [prev] | [next] | [standalone]
| From | J.J. O'Shea <try.not.to@but.see.sig> |
|---|---|
| Date | 2012-08-11 06:23 -0400 |
| Message-ID | <k05bqa0215q@news1.newsguy.com> |
| In reply to | #29310 |
On Sat, 11 Aug 2012 00:03:59 -0400, Michelle Steiner wrote (in article <michelle-15D0F2.21035810082012@news.eternal-september.org>): > In article <slrnk2blqq.144n.g.kreme@mbp55.local>, > Lewis <g.kreme@gmail.com.dontsendmecopies> wrote: > >>>>>> The firmware password is also easy to defeat, by adding or >>>>>> removing a RAM module and then resetting PRAM. So it's rather >>>>>> useless protectionif the intruder has physical access to the >>>>>> machine. >>>> >>>>> And not necessary if the intruder doesn't have physical access. >>>> >>>> There are degrees of physical access. You might have access to the >>>> machine to plug in a drive or put in a DVD, but not be able to open >>>> the machine to remove RAM, for example. >> >>> Got an example of how that would happen? >> >> High school computer lab with macbooks that are bolted to a metal plate. >> MacPros that have a cable lock through the side panel release, just to >> mention two I've seen. > > Someone who would want to hack a computer by removing RAM is not going to > be stopped by something like that if he's determined enough. > > It would, however, be obvious that he hacked it. And he'd need tools (a bolt cutter, for example) and could not possibly say that he'd done this by accident. That's also actual physical damage to company/school/whatever equipment, and _that_ can and usually will lead to not merely termination/expulsion but to criminal prosecution. -- email to oshea dot j dot j at gmail dot com.
[toc] | [prev] | [next] | [standalone]
| From | Michelle Steiner <michelle@michelle.org> |
|---|---|
| Date | 2012-08-11 07:39 -0700 |
| Message-ID | <michelle-0F2748.07391711082012@news.eternal-september.org> |
| In reply to | #29314 |
In article <k05bqa0215q@news1.newsguy.com>, J.J. O'Shea <try.not.to@but.see.sig> wrote: > >> High school computer lab with macbooks that are bolted to a metal > >> plate. MacPros that have a cable lock through the side panel release, > >> just to mention two I've seen. > > > > Someone who would want to hack a computer by removing RAM is not going > > to be stopped by something like that if he's determined enough. > > > > > > It would, however, be obvious that he hacked it. It would be obvious that someone hacked or stole it. Who did it is another matter. But once hacked like that, and the information stored therein stolen, it may not matter that the hacking was obvious. -- Tea Party Patriots is to Patriotism as People's Democratic Republic is to Democracy.
[toc] | [prev] | [next] | [standalone]
| From | J.J. O'Shea <try.not.to@but.see.sig> |
|---|---|
| Date | 2012-08-11 15:24 -0400 |
| Message-ID | <k06bgn02q35@news1.newsguy.com> |
| In reply to | #29317 |
On Sat, 11 Aug 2012 10:39:17 -0400, Michelle Steiner wrote (in article <michelle-0F2748.07391711082012@news.eternal-september.org>): > In article <k05bqa0215q@news1.newsguy.com>, > J.J. O'Shea <try.not.to@but.see.sig> wrote: > >>>> High school computer lab with macbooks that are bolted to a metal >>>> plate. MacPros that have a cable lock through the side panel release, >>>> just to mention two I've seen. >>> >>> Someone who would want to hack a computer by removing RAM is not going >>> to be stopped by something like that if he's determined enough. >>> >>> >> >> It would, however, be obvious that he hacked it. > > It would be obvious that someone hacked or stole it. Who did it is another > matter. But once hacked like that, and the information stored therein > stolen, it may not matter that the hacking was obvious. > Anyone who has data which must be secured should securely encrypt the data, using TrueCrypt or FileVault or similar, and a _good_ password. Then the presence or absence of a firmware password would be irrelevant. (Just having a password and basic encryption is not good enough, as it is possible to bypass the basic login passwords on both Macs and Windows systems quite easily; Google is your friend.) -- email to oshea dot j dot j at gmail dot com.
[toc] | [prev] | [next] | [standalone]
| From | Wes Groleau <Groleau+news@FreeShell.org> |
|---|---|
| Date | 2012-08-11 13:41 -0400 |
| Message-ID | <k065h0$m9j$2@dont-email.me> |
| In reply to | #29314 |
On 08-11-2012 06:23, J.J. O'Shea wrote:
> It would, however, be obvious that he hacked it. And he'd need tools (a bolt
> cutter, for example) and could not possibly say that he'd done this by
> accident. That's also actual physical damage to company/school/whatever
> equipment, and_that_ can and usually will lead to not merely
> termination/expulsion but to criminal prosecution.
Someone at my sons high school stole _all_23_ mouse balls from the
computer lab. I think the teacher in charge needs a new career.
--
Wes Groleau
There are more Baroque musicians than any other kind.
[toc] | [prev] | [next] | [standalone]
| From | JF Mezei <jfmezei.spamnot@vaxination.ca> |
|---|---|
| Date | 2012-08-11 14:12 -0400 |
| Message-ID | <5026a07b$0$44604$c3e8da3$460562f1@news.astraweb.com> |
| In reply to | #29327 |
I am not sure if I read this properly: with a firmware password, does this prevent someone from booting from a bootable DVD without first entering the firmware password ? If so, it would block most casual data theft assuming the computer was turned off (rarely happens these days) at time of theft. If the computer is turned on and locked at the password screen (either for login or for wake up), does a thief have the ability to cause the computer to reboot from DVD without enteting a firmware password ? Or is the firmware password invoked by EFI before any/all possible boot combinations ? Or putting the question differently: with a firmware password, is the only way around to boot from a DVD and access the disk drive to physically open the machine and disable the firmware password (or simply take the disk out and copy it from another machine) ?
[toc] | [prev] | [next] | [standalone]
| From | Lewis <g.kreme@gmail.com.dontsendmecopies> |
|---|---|
| Date | 2012-08-11 18:38 +0000 |
| Message-ID | <slrnk2d9kg.1cun.g.kreme@mbp55.local> |
| In reply to | #29329 |
In message <5026a07b$0$44604$c3e8da3$460562f1@news.astraweb.com> JF Mezei <jfmezei.spamnot@vaxination.ca> wrote: > I am not sure if I read this properly: > with a firmware password, does this prevent someone from booting from a > bootable DVD without first entering the firmware password ? Yes. > If so, it would block most casual data theft assuming the computer was > turned off (rarely happens these days) at time of theft. > If the computer is turned on and locked at the password screen (either > for login or for wake up), does a thief have the ability to cause the > computer to reboot from DVD without enteting a firmware password ? No. > Or is the firmware password invoked by EFI before any/all possible boot > combinations ? Yes, except the default one. There seems to be some issues with the "full" setting to the firmware password where it is supposed to ask for the password on every boot, regardless. I've never tried it. -- 'How do you know I'm mad?' said Alice 'You must be' said the Cat 'or you wouldn't have come here.'
[toc] | [prev] | [next] | [standalone]
| From | nospam <nospam@nospam.invalid> |
|---|---|
| Date | 2012-08-11 10:57 -0400 |
| Message-ID | <110820121057267335%nospam@nospam.invalid> |
| In reply to | #29310 |
In article <michelle-15D0F2.21035810082012@news.eternal-september.org>, Michelle Steiner <michelle@michelle.org> wrote: > > >> There are degrees of physical access. You might have access to the > > >> machine to plug in a drive or put in a DVD, but not be able to open > > >> the machine to remove RAM, for example. > > > > > Got an example of how that would happen? > > > > High school computer lab with macbooks that are bolted to a metal plate. > > MacPros that have a cable lock through the side panel release, just to > > mention two I've seen. > > Someone who would want to hack a computer by removing RAM is not going to > be stopped by something like that if he's determined enough. however, it will take a lot more time than just popping the cover and unseating a ram module. sure, they can do it, but they may not have that kind of time.
[toc] | [prev] | [next] | [standalone]
| From | Alan Browne <alan.browne@FreelunchVideotron.ca> |
|---|---|
| Date | 2012-08-10 14:37 -0400 |
| Message-ID | <9P6dnb_S8IhxybjNnZ2dnUVZ_t2dnZ2d@giganews.com> |
| In reply to | #29290 |
On 2012-08-10 14:14 , Király wrote:
> A useful scenario is an institutional sysadmin who manages a fleet of
> laptops, who doesn't want users to have admin access. He can set the
> firmware password, and then put a label over the RAM hatch that says
> "break this seal and you're fired/expelled."
So if someone comes in my office while I'm at lunch or in a meeting and
breaks the seal and it's attributed to me? ...
I wouldn't take possession of the thing if it had such a label for that
reason.
--
"Civilization is the limitless multiplication of unnecessary necessities."
-Samuel Clemens.
[toc] | [prev] | [next] | [standalone]
| From | me@home.spamsucks.ca (Király) |
|---|---|
| Date | 2012-08-10 23:46 +0000 |
| Message-ID | <k046g1$rdo$1@dont-email.me> |
| In reply to | #29293 |
Alan Browne <alan.browne@freelunchvideotron.ca> wrote: > So if someone comes in my office while I'm at lunch or in a meeting and > breaks the seal and it's attributed to me? ... > > I wouldn't take possession of the thing if it had such a label for that > reason. Yes, I agree, and it just illustrates further how useless the firmware password is. IME most people who ask about setting it assume it will protect them against something that it won't. -- K. Lang may your lum reek.
[toc] | [prev] | [next] | [standalone]
| From | Michael Vilain <vilain@NOspamcop.net> |
|---|---|
| Date | 2012-08-11 13:21 -0700 |
| Message-ID | <vilain-5733BB.13210911082012@news.individual.net> |
| In reply to | #29300 |
In article <k046g1$rdo$1@dont-email.me>, me@home.spamsucks.ca (Király) wrote: > Alan Browne <alan.browne@freelunchvideotron.ca> wrote: > > So if someone comes in my office while I'm at lunch or in a meeting and > > breaks the seal and it's attributed to me? ... > > > > I wouldn't take possession of the thing if it had such a label for that > > reason. > > Yes, I agree, and it just illustrates further how useless the firmware > password is. IME most people who ask about setting it assume it will > protect them against something that it won't. SUN workstations with a firmware password enabled required the replacement of the IDprom to override the password. And only a SUN hardware provider could supply that part (or a SUN employee). I had to replace a couple IDproms on workstations because they sometimes would get fried. It replaced the hardware ID on the system as well, so various software that was installed that used that ID stopped working. Calls to the vendor were also required once the part was replaced. It could be worse. It could be raining. -- DeeDee, don't press that button! DeeDee! NO! Dee... [I filter all Goggle Groups posts, so any reply may be automatically ignored]
[toc] | [prev] | [next] | [standalone]
| From | J.J. O'Shea <try.not.to@but.see.sig> |
|---|---|
| Date | 2012-08-11 06:23 -0400 |
| Message-ID | <k05bs01215q@news1.newsguy.com> |
| In reply to | #29293 |
On Fri, 10 Aug 2012 14:37:31 -0400, Alan Browne wrote (in article <9P6dnb_S8IhxybjNnZ2dnUVZ_t2dnZ2d@giganews.com>): > On 2012-08-10 14:14 , Király wrote: > >> A useful scenario is an institutional sysadmin who manages a fleet of >> laptops, who doesn't want users to have admin access. He can set the >> firmware password, and then put a label over the RAM hatch that says >> "break this seal and you're fired/expelled." > > So if someone comes in my office while I'm at lunch or in a meeting and > breaks the seal and it's attributed to me? ... You didn't take care of company equipment. > > I wouldn't take possession of the thing if it had such a label for that > reason. Then you wouldn't be working there for long. -- email to oshea dot j dot j at gmail dot com.
[toc] | [prev] | [next] | [standalone]
| From | nospam <nospam@nospam.invalid> |
|---|---|
| Date | 2012-08-10 15:11 -0400 |
| Message-ID | <100820121511241538%nospam@nospam.invalid> |
| In reply to | #29290 |
In article <k03j1q$4d3$1@dont-email.me>, Király <me@home.spamsucks.ca> wrote: > The firmware password is also easy to defeat, by adding or removing a > RAM module and then resetting PRAM. So it's rather useless protectionif > the intruder has physical access to the machine. unless you have a macbook air or retina macbook pro, where the memory is soldered and there's no way you can remove a ram module.
[toc] | [prev] | [next] | [standalone]
Page 1 of 2 [1] 2 Next page →
Back to top | Article view | comp.sys.mac.system
csiph-web