Live data from Hacker News

Apple EFI firmware passwords and the SCBO myth

reverse.put.as

1–10 of 38 posts

Re: Apple EFI firmware passwords and the SCBO myth

#4
post #3
post #2

TLDR? EFI password protection broken or not?

Yes.

What? That's not what it says at all!

Edit: I guess this is the slightly better answer than simply yes or no:

"If you lost your firmware password you can now reset it yourself as long the SPI flash chip is not the new BGA type (newer Macs are using them but there is a sneaky debug port that can be used for this same purpose!). You just need a device to dump the flash chip, remove the variable and reflash the modified version, or directly remove the variable (I always prefer to full dump and reflash). Of course this information can be used by thieves selling stolen Macs, but given that there are already defeat devices being sold all over the web, this post does not reveal any previously-unknown secrets."

Re: Apple EFI firmware passwords and the SCBO myth

#6
post #5

Apple is doing a much better job than all the rest of the PC vendors. Even those vendors that I haven't published keygens for [1] have just stupendously unsound bypass mechanisms for BIOS passwords. [1] https://dogber1.blogspot.com/2009/05/table-of-reverse-engine...

Seeing Compaq at the top of that table brought me all the way back...

Presario FTW!

Re: Apple EFI firmware passwords and the SCBO myth

#7
post #5

Apple is doing a much better job than all the rest of the PC vendors. Even those vendors that I haven't published keygens for [1] have just stupendously unsound bypass mechanisms for BIOS passwords. [1] https://dogber1.blogspot.com/2009/05/table-of-reverse-engine...

Seeing Compaq at the top of that table brought me all the way back... Presario FTW!

I wonder what PCs would be like if Intel bought Compaq in 1991 with people like Rod Canion and Jim Harris staying on. I think they were there when Compaq reverse engineered the IBM PC BIOS for example.

Re: Apple EFI firmware passwords and the SCBO myth

#8
post #5

Apple is doing a much better job than all the rest of the PC vendors. Even those vendors that I haven't published keygens for [1] have just stupendously unsound bypass mechanisms for BIOS passwords. [1] https://dogber1.blogspot.com/2009/05/table-of-reverse-engine...

Nevertheless, physical access still means it's game over; and I consider that a feature, not a bug. Given that, it's actually a little amusing that Apple went to all that effort for something that can be defeated with nothing more than a full BIOS reflash.

Re: Apple EFI firmware passwords and the SCBO myth

#9
These could be insiders working at Apple support centers or even Apple itself.

It makes me somewhat happy in a weird way to think that, even in notoriously locked-down and secretive companies like Apple, there are individuals who don't believe in and subvert the company's attempts to have sole control of its products. We have these individuals to thank for schematics, parts, and a lot of other material that feeds the third-party repair industry.

Re: Apple EFI firmware passwords and the SCBO myth

#10

These could be insiders working at Apple support centers or even Apple itself. It makes me somewhat happy in a weird way to think that, even in notoriously locked-down and secretive companies like Apple, there are individuals who don't believe in and subvert the company's attempts to have sole control of its products. We have these individuals to thank for schematics, parts, and a lot of other material that feeds the…

But these people are just signing password reset tokens. They're not in any way related to the people you're cheering for.
Post reply on HN