Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.sys.mac.system > #29288 > unrolled thread

firmware password

Started bydcohenspam@talktalk.net (Daniel Cohen)
First post2012-08-10 19:01 +0100
Last post2012-08-14 15:49 +0100
Articles 20 on this page of 29 — 12 participants

Back to article view | Back to comp.sys.mac.system


Contents

  firmware password dcohenspam@talktalk.net (Daniel Cohen) - 2012-08-10 19:01 +0100
    Re: firmware password me@home.spamsucks.ca (Király) - 2012-08-10 18:14 +0000
      Re: firmware password Michelle Steiner <michelle@michelle.org> - 2012-08-10 11:26 -0700
        Re: firmware password Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-10 20:20 +0000
          Re: firmware password Michelle Steiner <michelle@michelle.org> - 2012-08-10 13:27 -0700
            Re: firmware password nospam <nospam@nospam.invalid> - 2012-08-10 16:37 -0400
            Re: firmware password Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-11 03:54 +0000
              Re: firmware password Michelle Steiner <michelle@michelle.org> - 2012-08-10 21:03 -0700
                Re: firmware password J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-11 06:23 -0400
                  Re: firmware password Michelle Steiner <michelle@michelle.org> - 2012-08-11 07:39 -0700
                    Re: firmware password J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-11 15:24 -0400
                  Re: firmware password Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-11 13:41 -0400
                    Re: firmware password JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-11 14:12 -0400
                      Re: firmware password Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-11 18:38 +0000
                Re: firmware password nospam <nospam@nospam.invalid> - 2012-08-11 10:57 -0400
      Re: firmware password Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-10 14:37 -0400
        Re: firmware password me@home.spamsucks.ca (Király) - 2012-08-10 23:46 +0000
          Re: firmware password Michael Vilain <vilain@NOspamcop.net> - 2012-08-11 13:21 -0700
        Re: firmware password J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-11 06:23 -0400
      Re: firmware password nospam <nospam@nospam.invalid> - 2012-08-10 15:11 -0400
    Re: firmware password Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-10 20:15 +0000
      Re: firmware password dcohenspam@talktalk.net (Daniel Cohen) - 2012-08-11 12:18 +0100
    Re: firmware password Ant <ant@zimage.comANT> - 2012-08-11 14:12 -0700
      Re: firmware password Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-11 18:39 -0400
      Re: firmware password Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-12 02:22 +0000
      Re: firmware password billy@MIX.COM - 2012-08-12 03:55 +0000
        Re: firmware password dcohenspam@talktalk.net (Daniel Cohen) - 2012-08-12 14:27 +0100
          Re: firmware password billy@MIX.COM - 2012-08-14 03:06 +0000
            Re: firmware password dcohenspam@talktalk.net (Daniel Cohen) - 2012-08-14 15:49 +0100

Page 1 of 2  [1] 2  Next page →


#29288 — firmware password

Fromdcohenspam@talktalk.net (Daniel Cohen)
Date2012-08-10 19:01 +0100
Subjectfirmware password
Message-ID<1komcau.a6j0ko7lmxv8N%dcohenspam@talktalk.net>
I am considering setting a firmware password on my Mac.

Using Montain Lion, if I want to change startup disks using the option
key at startup I can do it provided I enter the firmware password.

From various discussion forums (it does not seem to be mentioned on
Apple's site) I get the impression that other things one might want to
do at startup (verbose mode, single-user mode) are not possible at all
when a firmware password is set, it isn't a matter of having to enter
the password to continue.

Am I right in this? If so, what actions are prohibited sompletely and
which trquite a password?

-- 
<http://www.decohen.com>
The Labyrinth of the Heart: Changed Myths for Changing Lives 
book and e-book <http://www.decohen.com/labyrinth>
Send e-mail to the Reply-To address, not the From address.

[toc] | [next] | [standalone]


#29290

Fromme@home.spamsucks.ca (Király)
Date2012-08-10 18:14 +0000
Message-ID<k03j1q$4d3$1@dont-email.me>
In reply to#29288
Daniel Cohen <dcohenspam@talktalk.net> wrote:
> I am considering setting a firmware password on my Mac.
> 
> Using Montain Lion, if I want to change startup disks using the option
> key at startup I can do it provided I enter the firmware password.
> 
> From various discussion forums (it does not seem to be mentioned on
> Apple's site) I get the impression that other things one might want to
> do at startup (verbose mode, single-user mode) are not possible at all
> when a firmware password is set, it isn't a matter of having to enter
> the password to continue.
> 
> Am I right in this? If so, what actions are prohibited sompletely and
> which trquite a password?

Setting the firmware password has one useful purpose - preventing users 
from gaining unauthorized admin access, by preventing them from booting 
into single user mode, or booting from DVD.

It does not, as many seem to believe, make one's data more secure from 
being stolen.

The firmware password is also easy to defeat, by adding or removing a 
RAM module and then resetting PRAM. So it's rather useless protectionif 
the intruder has physical access to the machine.

A useful scenario is an institutional sysadmin who manages a fleet of 
laptops, who doesn't want users to have admin access. He can set the 
firmware password, and then put a label over the RAM hatch that says 
"break this seal and you're fired/expelled."

Beyond that, there are few advantages to setting a firmware password.

-- 
K.

Lang may your lum reek.

[toc] | [prev] | [next] | [standalone]


#29292

FromMichelle Steiner <michelle@michelle.org>
Date2012-08-10 11:26 -0700
Message-ID<michelle-4DDB32.11265310082012@news.eternal-september.org>
In reply to#29290
In article <k03j1q$4d3$1@dont-email.me>, me@home.spamsucks.ca (Király) 
wrote:

> The firmware password is also easy to defeat, by adding or removing a 
> RAM module and then resetting PRAM. So it's rather useless protectionif 
> the intruder has physical access to the machine.

And not necessary if the intruder doesn't have physical access.

-- 
Tea Party Patriots is to Patriotism as 
People's Democratic Republic is to Democracy.

[toc] | [prev] | [next] | [standalone]


#29296

FromLewis <g.kreme@gmail.com.dontsendmecopies>
Date2012-08-10 20:20 +0000
Message-ID<slrnk2ar94.voq.g.kreme@mbp55.local>
In reply to#29292
In message <michelle-4DDB32.11265310082012@news.eternal-september.org> 
  Michelle Steiner <michelle@michelle.org> wrote:
> In article <k03j1q$4d3$1@dont-email.me>, me@home.spamsucks.ca (Király) 
> wrote:

>> The firmware password is also easy to defeat, by adding or removing a 
>> RAM module and then resetting PRAM. So it's rather useless protectionif 
>> the intruder has physical access to the machine.

> And not necessary if the intruder doesn't have physical access.

There are degrees of physical access. You might have access to the
machine to plug in a drive or put in a DVD, but not be able to open the
machine to remove RAM, for example.

It's another layer of security that can be very useful in certain situations.

-- 
Elves are wonderful. They provoke wonder.  Elves are marvellous. They
cause marvels.  Elves are fantastic. They create fantasies.  Elves are
glamorous. They project glamour.  Elves are enchanting. They weave
enchantment.  Elves are terrific. They beget terror.

[toc] | [prev] | [next] | [standalone]


#29297

FromMichelle Steiner <michelle@michelle.org>
Date2012-08-10 13:27 -0700
Message-ID<michelle-750CCD.13274410082012@news.eternal-september.org>
In reply to#29296
In article <slrnk2ar94.voq.g.kreme@mbp55.local>,
 Lewis <g.kreme@gmail.com.dontsendmecopies> wrote:

> >> The firmware password is also easy to defeat, by adding or removing a 
> >> RAM module and then resetting PRAM. So it's rather useless 
> >> protectionif the intruder has physical access to the machine.
> 
> > And not necessary if the intruder doesn't have physical access.
> 
> There are degrees of physical access. You might have access to the 
> machine to plug in a drive or put in a DVD, but not be able to open the 
> machine to remove RAM, for example.

Got an example of how that would happen?

-- 
Tea Party Patriots is to Patriotism as 
People's Democratic Republic is to Democracy.

[toc] | [prev] | [next] | [standalone]


#29298

Fromnospam <nospam@nospam.invalid>
Date2012-08-10 16:37 -0400
Message-ID<100820121637046897%nospam@nospam.invalid>
In reply to#29297
In article <michelle-750CCD.13274410082012@news.eternal-september.org>,
Michelle Steiner <michelle@michelle.org> wrote:

> > There are degrees of physical access. You might have access to the 
> > machine to plug in a drive or put in a DVD, but not be able to open the 
> > machine to remove RAM, for example.
> 
> Got an example of how that would happen?

macbook air.

[toc] | [prev] | [next] | [standalone]


#29308

FromLewis <g.kreme@gmail.com.dontsendmecopies>
Date2012-08-11 03:54 +0000
Message-ID<slrnk2blqq.144n.g.kreme@mbp55.local>
In reply to#29297
In message <michelle-750CCD.13274410082012@news.eternal-september.org> 
  Michelle Steiner <michelle@michelle.org> wrote:
> In article <slrnk2ar94.voq.g.kreme@mbp55.local>,
>  Lewis <g.kreme@gmail.com.dontsendmecopies> wrote:

>> >> The firmware password is also easy to defeat, by adding or removing a 
>> >> RAM module and then resetting PRAM. So it's rather useless 
>> >> protectionif the intruder has physical access to the machine.
>> 
>> > And not necessary if the intruder doesn't have physical access.
>> 
>> There are degrees of physical access. You might have access to the 
>> machine to plug in a drive or put in a DVD, but not be able to open the 
>> machine to remove RAM, for example.

> Got an example of how that would happen?

High school computer lab with macbooks that are bolted to a metal plate.
MacPros that have a cable lock through the side panel release, just to
mention two I've seen.

-- 
He [Vimes]'d never felt really at home with swords, but a cleaver was a
different matter. A cleaver had weight. It had purpose. A sword might
have a certain nobility about it, unless it was the one belonging for
example to Nobby, which relied on rust to hold it together, but what a
cleaver had was a tremendous ability to cut things up.

[toc] | [prev] | [next] | [standalone]


#29310

FromMichelle Steiner <michelle@michelle.org>
Date2012-08-10 21:03 -0700
Message-ID<michelle-15D0F2.21035810082012@news.eternal-september.org>
In reply to#29308
In article <slrnk2blqq.144n.g.kreme@mbp55.local>,
 Lewis <g.kreme@gmail.com.dontsendmecopies> wrote:

> >> >> The firmware password is also easy to defeat, by adding or 
> >> >> removing a RAM module and then resetting PRAM. So it's rather 
> >> >> useless protectionif the intruder has physical access to the 
> >> >> machine.
> >> 
> >> > And not necessary if the intruder doesn't have physical access.
> >> 
> >> There are degrees of physical access. You might have access to the 
> >> machine to plug in a drive or put in a DVD, but not be able to open 
> >> the machine to remove RAM, for example.
> 
> > Got an example of how that would happen?
> 
> High school computer lab with macbooks that are bolted to a metal plate. 
> MacPros that have a cable lock through the side panel release, just to 
> mention two I've seen.

Someone who would want to hack a computer by removing RAM is not going to 
be stopped by something like that if he's determined enough.

-- 
Tea Party Patriots is to Patriotism as 
People's Democratic Republic is to Democracy.

[toc] | [prev] | [next] | [standalone]


#29314

FromJ.J. O'Shea <try.not.to@but.see.sig>
Date2012-08-11 06:23 -0400
Message-ID<k05bqa0215q@news1.newsguy.com>
In reply to#29310
On Sat, 11 Aug 2012 00:03:59 -0400, Michelle Steiner wrote
(in article <michelle-15D0F2.21035810082012@news.eternal-september.org>):

> In article <slrnk2blqq.144n.g.kreme@mbp55.local>,
>  Lewis <g.kreme@gmail.com.dontsendmecopies> wrote:
> 
>>>>>> The firmware password is also easy to defeat, by adding or 
>>>>>> removing a RAM module and then resetting PRAM. So it's rather 
>>>>>> useless protectionif the intruder has physical access to the 
>>>>>> machine.
>>>> 
>>>>> And not necessary if the intruder doesn't have physical access.
>>>> 
>>>> There are degrees of physical access. You might have access to the 
>>>> machine to plug in a drive or put in a DVD, but not be able to open 
>>>> the machine to remove RAM, for example.
>> 
>>> Got an example of how that would happen?
>> 
>> High school computer lab with macbooks that are bolted to a metal plate. 
>> MacPros that have a cable lock through the side panel release, just to 
>> mention two I've seen.
> 
> Someone who would want to hack a computer by removing RAM is not going to 
> be stopped by something like that if he's determined enough.
> 
> 

It would, however, be obvious that he hacked it. And he'd need tools (a bolt 
cutter, for example) and could not possibly say that he'd done this by 
accident. That's also actual physical damage to company/school/whatever 
equipment, and _that_ can and usually will lead to not merely 
termination/expulsion but to criminal prosecution.

-- 
email to oshea dot j dot j at gmail dot com.

[toc] | [prev] | [next] | [standalone]


#29317

FromMichelle Steiner <michelle@michelle.org>
Date2012-08-11 07:39 -0700
Message-ID<michelle-0F2748.07391711082012@news.eternal-september.org>
In reply to#29314
In article <k05bqa0215q@news1.newsguy.com>,
 J.J. O'Shea <try.not.to@but.see.sig> wrote:

> >> High school computer lab with macbooks that are bolted to a metal 
> >> plate. MacPros that have a cable lock through the side panel release, 
> >> just to mention two I've seen.
> > 
> > Someone who would want to hack a computer by removing RAM is not going 
> > to be stopped by something like that if he's determined enough.
> > 
> > 
> 
> It would, however, be obvious that he hacked it. 

It would be obvious that someone hacked or stole it.  Who did it is another 
matter.  But once hacked like that, and the information stored therein 
stolen, it may not matter that the hacking was obvious.

-- 
Tea Party Patriots is to Patriotism as 
People's Democratic Republic is to Democracy.

[toc] | [prev] | [next] | [standalone]


#29332

FromJ.J. O'Shea <try.not.to@but.see.sig>
Date2012-08-11 15:24 -0400
Message-ID<k06bgn02q35@news1.newsguy.com>
In reply to#29317
On Sat, 11 Aug 2012 10:39:17 -0400, Michelle Steiner wrote
(in article <michelle-0F2748.07391711082012@news.eternal-september.org>):

> In article <k05bqa0215q@news1.newsguy.com>,
>  J.J. O'Shea <try.not.to@but.see.sig> wrote:
> 
>>>> High school computer lab with macbooks that are bolted to a metal 
>>>> plate. MacPros that have a cable lock through the side panel release, 
>>>> just to mention two I've seen.
>>> 
>>> Someone who would want to hack a computer by removing RAM is not going 
>>> to be stopped by something like that if he's determined enough.
>>> 
>>> 
>> 
>> It would, however, be obvious that he hacked it. 
> 
> It would be obvious that someone hacked or stole it.  Who did it is another 
> matter.  But once hacked like that, and the information stored therein 
> stolen, it may not matter that the hacking was obvious.
> 

Anyone who has data which must be secured should securely encrypt the data, 
using TrueCrypt or FileVault or similar, and a _good_ password. Then the 
presence or absence of a firmware password would be irrelevant. (Just having 
a password and basic encryption is not good enough, as it is possible to 
bypass the basic login passwords on both Macs and Windows systems quite 
easily; Google is your friend.)

-- 
email to oshea dot j dot j at gmail dot com.

[toc] | [prev] | [next] | [standalone]


#29327

FromWes Groleau <Groleau+news@FreeShell.org>
Date2012-08-11 13:41 -0400
Message-ID<k065h0$m9j$2@dont-email.me>
In reply to#29314
On 08-11-2012 06:23, J.J. O'Shea wrote:
> It would, however, be obvious that he hacked it. And he'd need tools (a bolt
> cutter, for example) and could not possibly say that he'd done this by
> accident. That's also actual physical damage to company/school/whatever
> equipment, and_that_  can and usually will lead to not merely
> termination/expulsion but to criminal prosecution.

Someone at my sons high school stole _all_23_ mouse balls from the 
computer lab.  I think the teacher in charge needs a new career.

-- 
Wes Groleau

    There are more Baroque musicians than any other kind.

[toc] | [prev] | [next] | [standalone]


#29329

FromJF Mezei <jfmezei.spamnot@vaxination.ca>
Date2012-08-11 14:12 -0400
Message-ID<5026a07b$0$44604$c3e8da3$460562f1@news.astraweb.com>
In reply to#29327
I am not sure if I read this properly:

with a firmware password, does this prevent someone from booting from a
bootable DVD  without first entering the firmware password ?

If so, it would block most casual data theft assuming the computer was
turned off (rarely happens these days) at time of theft.

If the computer is turned on and locked at the password screen (either
for login or for wake up), does a thief have the ability to cause the
computer to reboot from DVD without enteting a firmware password ?

Or is the firmware password invoked by EFI before any/all possible boot
combinations ?

Or putting the question differently: with a firmware password, is the
only way around  to boot from a DVD and access the disk drive to
physically open the machine and disable the firmware password (or simply
take the disk out and copy it from another machine)  ?

[toc] | [prev] | [next] | [standalone]


#29330

FromLewis <g.kreme@gmail.com.dontsendmecopies>
Date2012-08-11 18:38 +0000
Message-ID<slrnk2d9kg.1cun.g.kreme@mbp55.local>
In reply to#29329
In message <5026a07b$0$44604$c3e8da3$460562f1@news.astraweb.com> 
  JF Mezei <jfmezei.spamnot@vaxination.ca> wrote:
> I am not sure if I read this properly:

> with a firmware password, does this prevent someone from booting from a
> bootable DVD  without first entering the firmware password ?

Yes.

> If so, it would block most casual data theft assuming the computer was
> turned off (rarely happens these days) at time of theft.

> If the computer is turned on and locked at the password screen (either
> for login or for wake up), does a thief have the ability to cause the
> computer to reboot from DVD without enteting a firmware password ?

No.

> Or is the firmware password invoked by EFI before any/all possible boot
> combinations ?

Yes, except the default one.

There seems to be some issues with the "full" setting to the firmware
password where it is supposed to ask for the password on every boot,
regardless. I've never tried it.

-- 
'How do you know I'm mad?' said Alice 'You must be' said the Cat 'or you
wouldn't have come here.'

[toc] | [prev] | [next] | [standalone]


#29321

Fromnospam <nospam@nospam.invalid>
Date2012-08-11 10:57 -0400
Message-ID<110820121057267335%nospam@nospam.invalid>
In reply to#29310
In article <michelle-15D0F2.21035810082012@news.eternal-september.org>,
Michelle Steiner <michelle@michelle.org> wrote:

> > >> There are degrees of physical access. You might have access to the 
> > >> machine to plug in a drive or put in a DVD, but not be able to open 
> > >> the machine to remove RAM, for example.
> > 
> > > Got an example of how that would happen?
> > 
> > High school computer lab with macbooks that are bolted to a metal plate. 
> > MacPros that have a cable lock through the side panel release, just to 
> > mention two I've seen.
> 
> Someone who would want to hack a computer by removing RAM is not going to 
> be stopped by something like that if he's determined enough.

however, it will take a lot more time than just popping the cover and
unseating a ram module. sure, they can do it, but they may not have
that kind of time.

[toc] | [prev] | [next] | [standalone]


#29293

FromAlan Browne <alan.browne@FreelunchVideotron.ca>
Date2012-08-10 14:37 -0400
Message-ID<9P6dnb_S8IhxybjNnZ2dnUVZ_t2dnZ2d@giganews.com>
In reply to#29290
On 2012-08-10 14:14 , Király wrote:

> A useful scenario is an institutional sysadmin who manages a fleet of
> laptops, who doesn't want users to have admin access. He can set the
> firmware password, and then put a label over the RAM hatch that says
> "break this seal and you're fired/expelled."

So if someone comes in my office while I'm at lunch or in a meeting and 
breaks the seal and it's attributed to me? ...

I wouldn't take possession of the thing if it had such a label for that 
reason.


-- 
"Civilization is the limitless multiplication of unnecessary necessities."
             -Samuel Clemens.

[toc] | [prev] | [next] | [standalone]


#29300

Fromme@home.spamsucks.ca (Király)
Date2012-08-10 23:46 +0000
Message-ID<k046g1$rdo$1@dont-email.me>
In reply to#29293
Alan Browne <alan.browne@freelunchvideotron.ca> wrote:
> So if someone comes in my office while I'm at lunch or in a meeting and 
> breaks the seal and it's attributed to me? ...
> 
> I wouldn't take possession of the thing if it had such a label for that 
> reason.

Yes, I agree, and it just illustrates further how useless the firmware 
password is. IME most people who ask about setting it assume it will 
protect them against something that it won't.

-- 
K.

Lang may your lum reek.

[toc] | [prev] | [next] | [standalone]


#29334

FromMichael Vilain <vilain@NOspamcop.net>
Date2012-08-11 13:21 -0700
Message-ID<vilain-5733BB.13210911082012@news.individual.net>
In reply to#29300
In article <k046g1$rdo$1@dont-email.me>, me@home.spamsucks.ca (Király) 
wrote:

> Alan Browne <alan.browne@freelunchvideotron.ca> wrote:
> > So if someone comes in my office while I'm at lunch or in a meeting and 
> > breaks the seal and it's attributed to me? ...
> > 
> > I wouldn't take possession of the thing if it had such a label for that 
> > reason.
> 
> Yes, I agree, and it just illustrates further how useless the firmware 
> password is. IME most people who ask about setting it assume it will 
> protect them against something that it won't.

SUN workstations with a firmware password enabled required the 
replacement of the IDprom to override the password.  And only a SUN 
hardware provider could supply that part (or a SUN employee).  I had to 
replace a couple IDproms on workstations because they sometimes would 
get fried.  It replaced the hardware ID on the system as well, so 
various software that was installed that used that ID stopped working.  
Calls to the vendor were also required once the part was replaced.

It could be worse. It could be raining.

-- 
DeeDee, don't press that button!  DeeDee!  NO!  Dee...
[I filter all Goggle Groups posts, so any reply may be automatically ignored]

[toc] | [prev] | [next] | [standalone]


#29315

FromJ.J. O'Shea <try.not.to@but.see.sig>
Date2012-08-11 06:23 -0400
Message-ID<k05bs01215q@news1.newsguy.com>
In reply to#29293
On Fri, 10 Aug 2012 14:37:31 -0400, Alan Browne wrote
(in article <9P6dnb_S8IhxybjNnZ2dnUVZ_t2dnZ2d@giganews.com>):

> On 2012-08-10 14:14 , Király wrote:
> 
>> A useful scenario is an institutional sysadmin who manages a fleet of
>> laptops, who doesn't want users to have admin access. He can set the
>> firmware password, and then put a label over the RAM hatch that says
>> "break this seal and you're fired/expelled."
> 
> So if someone comes in my office while I'm at lunch or in a meeting and 
> breaks the seal and it's attributed to me? ...

You didn't take care of company equipment.

> 
> I wouldn't take possession of the thing if it had such a label for that 
> reason.

Then you wouldn't be working there for long.


-- 
email to oshea dot j dot j at gmail dot com.

[toc] | [prev] | [next] | [standalone]


#29294

Fromnospam <nospam@nospam.invalid>
Date2012-08-10 15:11 -0400
Message-ID<100820121511241538%nospam@nospam.invalid>
In reply to#29290
In article <k03j1q$4d3$1@dont-email.me>, Király <me@home.spamsucks.ca>
wrote:

> The firmware password is also easy to defeat, by adding or removing a 
> RAM module and then resetting PRAM. So it's rather useless protectionif 
> the intruder has physical access to the machine.

unless you have a macbook air or retina macbook pro, where the memory
is soldered and there's no way you can remove a ram module.

[toc] | [prev] | [next] | [standalone]


Page 1 of 2  [1] 2  Next page →

Back to top | Article view | comp.sys.mac.system


csiph-web