Grub is password-protected, what do you do? (Boot from a live distro and chroot into the on-disk one)
This is what came to me first. I have unrestricted physical access? I probably own the machine. If the data on the storage is not encrypted, I own that too. If I don't want to disassemble anything, I just plug in a liveUSB and it's all mine. If the BIOS has USB/CD boot disabled? I pull the CMOS battery. If that fails? The google probably knows the BIOS reset sequence for your board and soon so will I. ===============…
If properly secured, physical hacking is not as easy as it used to be.