Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Lots of work/school computer has a password locked BIOS which prevents you from booting from anything else. If they also have a physical lock on the computer, or if it's a laptop that you can't open or doesn't have a bios reset functionality, or you're worried about getting caught opening the computer, you're effectively locked out.

This exploit does actually open possibilities where there were few/none before. Also I imagine it's easier for some people to execute.



This password locking is worthless - most (if not all) BIOSes have backdoor password that allows anyone to bypass password lock.

Here's one of the pages that lists some of them: http://www.uktsupport.co.uk/reference/biosp.htm


Some devices make this very difficult. Well, not very difficult - just more time consuming. I was trying to unlock a BIOS password on a Toshiba Satellite maybe 3 years ago, none of the default or "backdoor" passwords would work. However, you were able to reset it by using a jumper to complete a specific part of the circuit.. Not for the faint hearted, however if a thief steals the laptop, they'll have no problem opening it up in their own time.

I'm glad they've made this harder, as most thieves are deterred by the technical aspects of breaking in to wipe a computer.


Don't even get me started on the passwords to unlock HDD's, the ones you set on the BIOS... One day I will write how I unlocked the Toshiba(TSSTCorp) HDD I had forgotten the password for on my laptop. I had to buy a new HDD, because I didn't have a spare one at the time, but I did it in less than 5 minutes, unscrewing and screwing the laptop covers and HDD's included. They weren't even the same brand. I bought a Samsung to unlock the Hitachi.


Also you could probably reset the bios in a couple minutes.


I refuse to use lab computers on this basis. I assume they're owned and have keyloggers. I'd sooner use someone else's toothbrush.

I don't understand why more labs don't use dumb terminals to hook back into a VM that gets blown out the airlock after each and every use.


It's not very hard to build a keylogger using basic pic chips and install them into a keyboard. The same could be done against a dumb terminal. For bonus points, put a bluetooth module / picoduino inside so that you can read out people's keystrokes without touching it again.


Cost and complexity of administration most likely.


Also time, our university did something like this on their library computers. It meant waiting 5min after someone logged out for it to do a system restore before the next person could log in. Which seemed like forever when you're rushing to print a paper.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: