Question: how secure are BIOS passwords, really? If you have full-disk encryption anyway, is the BIOS password adding anything?
Defeating a Laptop's BIOS Password
31–40 of 100 posts
Re: Defeating a Laptop's BIOS Password
#32A lot of passwords can be derived from the serial number. This website will do a lot of the work for you. https://bios-pw.org/
That's a great re-implementation from some stuff I did eons ago [0]. BIOS passwords are indeed a complete joke as means to secure access. There are a bunch of vendors out there who moved the authentication off from the BIOS/CPU to the KBC (keyboard controller) - Toshiba and Lenovo are among them. Still, it's ludicrously easy to circumvent these. [0] https://dogber1.blogspot.com/2009/05/table-of-reverse-engine...
Re: Defeating a Laptop's BIOS Password
#33Earlier quoted context omitted.
A bit, as posted in this blog, but for most part having physical unlimited access to a device it's game over. Hence why encrypting your sensitive data should be the norm (I am aware that is not the norm, not by far)
Sure, it's just that the only situation I see a BIOS password making sense is in the presence of some intrusion-detection mechanism that would perform some kind of destruction/lockdown/alarm so that attempting to bypass it would not be without consequences.
Re: Defeating a Laptop's BIOS Password
#34Earlier quoted context omitted.
That's a great re-implementation from some stuff I did eons ago [0]. BIOS passwords are indeed a complete joke as means to secure access. There are a bunch of vendors out there who moved the authentication off from the BIOS/CPU to the KBC (keyboard controller) - Toshiba and Lenovo are among them. Still, it's ludicrously easy to circumvent these. [0] https://dogber1.blogspot.com/2009/05/table-of-reverse-engine...
The linked article did not have info about Thinkpads. I wonder how nowadays one can skip BIOS password of a T series thinkpad. So far it has always ended up with a motherboard change for me.
Re: Defeating a Laptop's BIOS Password
#35Earlier quoted context omitted.
That's a great re-implementation from some stuff I did eons ago [0]. BIOS passwords are indeed a complete joke as means to secure access. There are a bunch of vendors out there who moved the authentication off from the BIOS/CPU to the KBC (keyboard controller) - Toshiba and Lenovo are among them. Still, it's ludicrously easy to circumvent these. [0] https://dogber1.blogspot.com/2009/05/table-of-reverse-engine...
The linked article did not have info about Thinkpads. I wonder how nowadays one can skip BIOS password of a T series thinkpad. So far it has always ended up with a motherboard change for me.
Re: Defeating a Laptop's BIOS Password
#36There are quite a few laptops on ebay at considerable discounts because the seller doesn't know the BIOS password. This could come in handy.
I'm not sure buying stolen laptops is really the direction we want to go in here.
Re: Defeating a Laptop's BIOS Password
#37Re: Defeating a Laptop's BIOS Password
#38Oh sure, to defeat a BIOS password I'm supposed to have IDA Pro lying around, with license.
Re: Defeating a Laptop's BIOS Password
#39I was of the impression that BIOS passwords were in general not something one should rely even as a layer when assuming physical access. In the (not that) old days it was usually just a matter of removing the internal battery to reset it. Has this assumption changed in past years?
Re: Defeating a Laptop's BIOS Password
#40I get that this is kind of content marketing for their engineering department, but damn if they could've prooooobably spent that money on something with more impact