Apple Includes Open Firmware Password App

Itis not part of a basic install, and Apple has not drawn any attention to it, but an application called Open Firmware Password that is similar to the classic Mac OS "Password Security" has been included on the Mac OS X 10.1 CD. On the CD you can find the application at:

Mac OS X Install CD:Applications:Utilities

When you first run Open Firmware Password, you are presented with a window that says "The Open Firmware password is used to prevent others from starting your computer with a different disk. This makes your computer more secure."

WARNING!!!!!

The Mac Observer urges caution in using this or any firmware password application. Misuse could result in an unbootable system or worse. Firmware operates at the lowest level of the Mac. The data does not reside on any hard drive, so a reformat would be useless in reversing any misfortune. In Appleis case, caution is especially warranted since the utility includes no documentation or help files.

To add or change the password, you must click on the lock symbol in the lower left of the window and enter an administratoris password (see image).

This takes you to a window where you can choose to have a password required for starting your Mac up from another disk, and either enter or change that password (see image).

An article from Appleis Knowledge Base notes that recent firmware updates for newer Macs have added "support for additional security options that allow the Open Firmware to be password-protected." The programis about box states, "Use this application to set the security mode and password for Open Firmware. Enabling this feature provides IEEE1275 compliant security for your system." (See Image)

Interestingly, the application cannot be fully copied from the CD. Even logging in as root copies only 88K of the 120K application. Examining the packageis contents reveal that some components simply wonit move off the CD, producing a non-functional application on the target volume. There may be a very good reason not to run this program from a local hard disk, but as of yet, Apple has not provided any information to its users regarding this powerful programis operation. To our knowledge, this is the first time that Apple has taken such measures to prevent an application from being copied from a CD.

You can get more information on IEEE 1275 by doing a search for 1275-1994 on the Institute of Electrical and Electronics Engineersi Web site.

In the weeks leading up to 10.1is release, Digital Specter released Startup Security (currently at version 1.2) for $19.95 on both OS 9 and X which makes use of the same firmware feature.