Using EFI password "full" security isn't working

Hi,
I'm trying to use the EFI Password Utility to prohibit any attempt to boot my MacBook Pro without the correct password.  I used the utility available on the MacBook Pro's supplied install DVD, and so far have successfully prevented the use of any keystrokes on boot without the correct password (ie. "command" mode).  However, I am unable to set the EFI to prohibit any attempt to boot.
Apple documents in its, "Mac OS X: Security Configuration - For Mac OS X Version 10.6 Snow Leopard" PDF manual that,
You can also configure EFI from the command line by using the nvram tool. […] 
You can set the security mode to one of the following values:
     Full: This value requires a password to start up or restart your computer. It also requires a password to make changes to EFI.
For example, to set the security-mode to full you would use the following command:
     $ sudo nvram security-mode=full
I applied this setting, but it doesn't appear to be working.  The redacted output of "nvram -x -p" is as follows:
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
          <key>EFICapsule_Result</key>
          <data>
          REDACTED
          </data>
          <key>SmcFlasherResult</key>
          <data>
          REDACTED
          </data>
          <key>SystemAudioVolume</key>
          <data>
          REDACTED
          </data>
          <key>boot-image</key>
          <data>
          REDACTED
          </data>
          <key>efi-apple-payload0</key>
          <data>
          REDACTED
          </data>
          <key>efi-apple-payload0-data</key>
          <data>
          REDACTED
          </data>
          <key>efi-apple-recovery</key>
          <data>
          REDACTED
          </data>
          <key>efi-boot-device</key>
          <data>
          REDACTED
          </data>
          <key>efi-boot-device-data</key>
          <data>
          REDACTED
          </data>
          <key>gpu-policy</key>
          <data>
          REDACTED
          </data>
          <key>prev-lang:kbd</key>
          <data>
          REDACTED
          </data>
          <key>security-mode</key>
          <string>full</string>
</dict>
</plist>
What makes it confusing is that Apple specifies later on the same page (56) that the the term passed to the "security-mode" option should be encased in quotes:
# Secure startup by setting security-mode. Replace $mode-value with # "command" or "full."
     sudo nvram security-mode="$mode-value"
So, assuming that I may have used the wrong version of the command, and thereby not applied the setting correctly, I deleted the "security-mode" key using:
sudo nvram -d security-mode
I then re-applied the setting using:
sudo nvram security-mode=full
because I was confident that, initially, I had used the version with quotes.  However, it's made no difference - booting the machine does not require entry of an EFI password.
Oddly, the EFI still prevents the use of keystrokes (ie. "command" mode), so it's definitely functional; I just can't tell it to use "full" mode.  Also, I note that "security-mode" is the only key to have a "string" child not a "data" child - is this indicative of a problem?
Any advice?

I've got the same problem as OP but I'm not concerning myself with the physical security of my device--an entirely separate topic altogether.
Essentially, I know that with physical access to a Mac box it's possible to enter single user mode and change the password. I also know there is a way to prevent that ability by changing the default login credentials I just don't remember the phrase of what I'm looking for. I know that I have a pdf on hardening snow leopard which probably has information on how to restrict password changes when in single user mode, but I can't find it.
Here's some stuff that should at least get you started in the right direction:
http://support.apple.com/kb/HT1352
http://lists.apple.com/archives/fed-talk/2011/Feb/msg00022.html
Definitely read:
http://www.nsa.gov/ia/_files/factsheets/macosx_10_6_hardeningtips.pdf
Depending how much time you want to spend on this, there's also a book by Charlie Miller called "Mac Hackers Handbook" that's worth the read--although I have yet to do completely so myself. I did get to see his talk at DefCon 2011 and it was pretty amazing- he developed a technique to essentially make a Mac laptop battery explode from a remote location-- although he never has actually done it for fear of...you know...actually destroying his computer. lol. The next time you hear a MacTard bragging about how OSX is a secure platform, be sure to bring that up. Also distinguish between viruses and malware in general the next time you talk to a genius about mac security- we recently discovered a rootkit on one of the Macs on our network.
Back to the topic--If you're going to go through the effort of securing one aspect of your box, you mind as well keep going with it if you have legitimate reasons to worry about unauthorized access.
Another awesome resource is the Electronic Frontier Foundation:
https://www.eff.org
https://ssd.eff.org/risk
They have guides about nearly everything concerning online anonymity and/or security and they're really good about keeping it 'human readable' - ie understandable to the average user. I'll try to find that pdf and upload it if I do. Those other resources should point you in the right direction- if not explicitly answer your question. Let me know if you find anything too . Help me help you.
<Edited by Host>

Similar Messages

  • Reboot needs password and admin isn't working.

    I dropped my MacBook Pro about 12 inches today. Since then, it wasn't running correctly, so I forced a shut down. Now when I try to restart, it's getting stuck on the gray screen with the apple symbol and a spiral.
    I'm trying to do the command r reboot, but I get a screen with a lock and password line. I have tried using my admin password, but it's not working.
    This is a work computer and I'm on sabbatical this year. Anyone know if there is anything I can do?
    TIA

    Your old email and password are still an Apple ID, and they are the one that you did the subscription with. So you will have to sign onto that old ID in order to cancel the subscription.
    Cheers,
    GB

  • I'm trying to forward icloud email to gmail.  I used the forwarding tool which isn't working.

    THe forwarding tool isn't working.  I also set up rules and that isn't working.  Any ideas of what to try next?  People often email me @mac.com -- super old school, I know.  Is that the problem?  I set up a rule for that too. 

    sign on to icloud.com with your icloud user name and forward emails from icloud to gmail that way. those rules are tricky. but that is what worked for me.

  • I have a listbox with propety nodes "Item names" and "Double click".I'm trying to access the files in the listbox using these nodes but it isn't working. How exactly does Items names work??

    I realise that the first item in the listbox is 0 but how can I open these files in the listbox...I'm very confused!!

    I have attached an example to help you out. Let me know if this is what your looking for.
    Good luck,
    Greg
    Attachments:
    listbox.vi ‏30 KB

  • The password features does not work. Open TB, and I can read my email without using the password. Why?

    I use a password for security. When I click onto TB, I do not have to use my password to read my emails or it will not download. I cannot figure out how to change my password. When I tried to set the master password,
    it claims to have confirmed the new one. But I have to use the old password, or I do not have to use a password at all to read my email, if it downloads. This is after I uninstalled and installed TB 24.4 three times.
    Now what, any ideas?

    Here is my understanding: the master password secures your saved passwords. In other works, it unlocks your password to connect to the server to send and receive mail. It doesn't prevent people who have access to your computer from opening Thunderbird and seeing what's already there.
    This article has an extended discussion of many methods to try to prevent others from reading your already downloaded mail: http://kb.mozillazine.org/Protecting_the_contents_of_the_profile_-_mail

  • PDF Windows isn't working

    Good day all here!
    Some days ago - I don't remember after a Windows-7-Professional (64 Bit) and/or and Adobe-Update (they took place on the same day) Acrobat 8.0 Professional (I still use Creative Suite 3.2) isn't working correct anymore. Opening a PDF results in a courrpted presentation mainly without the windows-page-frame and the options-bar of Adobe Acrobat. I can't close the PDF normaly (no "x" visible) and only sometimes when I switch it into the taks bar and back on it works - or not. I'm able to open Acrobat normal by doulbe clicking the icon and when I move a PDF into it seems to works fine.
    I would be thankful for any help - thanks a lot!
    Bert Groner
    Lenzkirch-Saig

    I have also gone to Adobe Reader XI signed on....went to create PDF (1
    FILE/211kb) then it uploaded file to online...then conveting file to PDF
    using Adobe Create PDF Online- THEN after about 6 minutes it said "the
    conversion failed because the file is taking too long to process".....then
    I received this email:
    Adobe PDF Pack could not successfully convert your file *2014 ORANGE SYRUP
    LABEL.pub* to Adobe PDF. The conversion of your uploaded file timed out.You
    can try to convert the file to Adobe PDF via Adobe CreatePDF Desktop Printer
    <http://createpdf.acrobat.com/static/assets/win/AdobeCreatePDFDesktopPrinterSetup.exe>
    from
    virtually any application.
    On Mon, Aug 11, 2014 at 7:19 PM, Graham Eipper <

  • I keep getting the message password is incorrect how do I get past this?  I've tried entering the correct password numerous times, still not working!

    I keep getting password incorrect upon starting my Ipad, I have tried to enter the correct password but still isn't working and I can't get past this and to get into my settings to fix.  Help?

    Paste these two links into your browser and have a read -
    http://support.apple.com/kb/HT1212
    http://www.everymac.com/systems/apple/ipad/ipad-troubleshooting-repair-faq/ipad- how-to-unlock-open-forgot-code-passcode-password-login.html

  • Ai changed my email for my apple id, but i can't change my iCloud ccount because i can't remember my old password, and now i need to use iCloud for my new IPhone but it isn't working, how do i fix that?

    i changed my email for my apple id, but i can't change my iCloud  account because i can't remember my old password, and now i need to use iCloud for my new IPhone but it isn't working, how do i fix that?

    If the old ID is yours, and if your new ID was created by editing the details of this old ID (rather than being an entirely new ID), go to https://appleid.apple.com, click Manage my Apple ID and sign in with your current iCloud ID.  Click edit next to the primary email account, change it back to your old email address and save the change.  Then edit the name of the account to change it back to your old email address.  You can now use your current password to turn off Find My iDevice, even though it prompts you for the password for your old account ID. Then save any photo stream photos that you wish to keep to your camera roll.  When finished go to Settings>iCloud, tap Delete Account and choose Delete from My iDevice when prompted (your iCloud data will still be in iCloud).  Next, go back to https://appleid.apple.com and change your primary email address and iCloud ID name back to the way it was.  Now you can go to Settings>iCloud and sign in with your current iCloud ID and password.

  • The password I use for installing downloaded applications or installing basically anything isn't working but I didn't change it or let alone touched it. How do I fix this? I'm on an iMac 21.5 inch, Mid 2011 and Mac OS X Version 10.7.3

    The password I use for installing downloaded applications or installing basically anything isn't working but I didn't change it or let alone touched it. How do I fix this? I'm on an iMac 21.5 inch Mid 2011 and Mac OS X Version 10.7.3

    I've no idea why it has stopped working, but you could reset it:
    http://osxdaily.com/2011/08/24/reset-mac-os-x-10-7-lion-password/

  • The password I use for installing downloaded applications or installing basically anything isn't working but I didn't change it or let alone touched it. How do I fix this?

    The password I use for installing downloaded applications or installing basically anything isn't working but I didn't change it or let alone touched it. How do I fix this?

    iMac 21.5-inch Mid 2011
    Mac OS X Version 10.7.3

  • Just got a new IPOD Touch and it wont connect to our Wifi home network with a Belken N Router. Our router uses WEP 64 bit security, but had a "blank" password field, which the IPOD did not like. Changing to a 6 char numeric PW didnt help either.

    OS is whatever OS ships with current IPOD Touch
    I cannot understand why the APPLE engineers have designed this product so that it has SO MANY WIFI problems.  This is supposed to be an easy-to-use product.  We've had no problems connecting our new laptop, our ROKU box, etc, but it seems impossible to get the IPOD touch to work.  NOTHING LIKE SPENDING XMAS MORNING DOING APPLE TECH SUPPORT TROUBLESHOOTING TO LEAVE YOU IN THE CHRISTMAS SPIRIT!!!  Argh!
    In fact, the only way we have been able to get this expensive brand new IPOD to work on our home network is to DISABLE SECURITY in the router settings.  THIS IS ANYTHING BUT A GOOD IDEA.
    DON"T KNOW WHY BUT MANY OTHER USERS ARE REPORTING THE SAME KIND OF PROBLEM SO APPLE ENGINEERING NEEDS TO GET BUSY AND FIX THIS PROBLEM SO THAT NEW USERS CAN CONNECT TO THE INTERNET WITHOUT HAVING TO BE TRAINED ROUTER ENGINEERS TO DO IT!!!!
    Ok, sorry for the rant, but surely those of you who are experiencing this share my frustration.  This is not why I bought an APPLE product.
    IS THERE ANY POSSIBILITY THAT APPLE WILL NOT ALLOW A WIFI PASSWORD with more than one identical alphanumeric character?  Any ideas?  We also tried eliminating the 40 MHZ setting under Bandwidth settings in the router settings for our router, but it made no difference.  The router has the latest firmware, too.  Running out of ideas, and am ready to box this unit up and send it back!

    Thanks, Bob!  You are correct.  And, we learned this as we spoke with APPLE TECH SUPPORT by phone on Christmas day (800-APL-CARE).  One of their reps spent the time to help us troubleshoot this, but the boiled down conclusion is your answer, and to repeat for the benefit of others, here is what worked:
    1. With our Belkin router set to "out-of-the-box" WEP 64 bit security, we could not get wireless access of any kind.  Only with the Security Mode set to DISABLED, could we gain access.
    2. Changing the router's security mode setting to "WPA/WPA-2...." and entering a new min. 8 char passphrase, and then entering that same passphrase into the IPOD Touch, and restarting the router, did the trick!
    Based on this, and some info found in another posting, I can only conclude that the IPODs and IPHONES do not support WEP security mode in many generic routers used by thousands of consumers.  Hopefully, those same consumers can figure out how to change their wireless router setttings to WPA/WPA-2 security mode and ALSO get all their other wireless devices (PCs, laptops, WII boxes, ROKU boxes) all reconfigured to WPA mode, too.
    I THINK THE BOTTOM LINE HERE IS THAT THERE IS AN ISSUE THAT APPLE NEEDS TO ADDRESS WITH WEP COMPATIBILITY and it may also be the case that MOST CONSUMERS ARE USING WEP 64 BIT security on their home wireless routers?
    In any case, it's working now, so anyone who is having problems should try changing to WPA mode and post back here if it worked for them!

  • I cannot access my old email address anymore, however I have used it for my apple ID and now I want to delete it because the account has never been verified in the first place so my password for it doesn't work. What do I do?

    I cannot access my old email address anymore, however I have used it for my apple ID and now I want to delete it because the account has never been verified in the first place so my password for it doesn't work. So when I want to download apps I have to sign in with apple id but I can't so I made a new one, However I can't seem to be able to delete the old one. What do I do?

    You can't merge Apple IDs.  You also can't cancel (delete) and existing ID, you can only choose to stop using it.
    If your old ID was compromised and you can no longer access it, you'll have to contact Apple for assistance.  Go to https://expresslane.apple.com ; click 'See all products and services' at the bottom of the page. In the next page click 'More Products and Services, then 'Apple ID'. In the next page select 'Other Apple ID Topics' then then 'Apple ID account Security’.

  • Authorisation of an old account on a new mac, Password not working, no longer have access to that email address, and security question not working. But I do have my mac authorised! ...is there anyway to copy or get authorisation info off it???

    Please help me!!!!
    I have got a new Mac, I am trying to share my itues on it as well as my old mac, I have had two itunes accounts in my life, one is current now (this account) one I have not had access to the email for years. Since I have bought music off both accounts, I wish to play it all on  both my macs. My Old mac has both accounts Authorised fine and all is good.
    My new Mac, I have thios account running fine, but keep getting prompted for the password for my old account, I have no idea what my old password is, I have not had access to that email address for 5 years, and for some strange reason the security question isn't working eaither.
    Since I do still have one Mac where it is Authorised, Is there any file I can copy accross or anyway to get the password out of the OSX 10.6.8 for my old account.
    Secondly, is there anyway to roll both accounts into just my current one.
    Many Thanks in advance for your help.
    Steve

    I too am having this same problem but I have not seen ANY solutions for it. Looks like Apple is ignoring it!!!!!!!!?

  • Why blocking sites using Hosts file isn't working?

    Hello 
    I need to block a few websites on my home computer. Did a quick search and found out I had to work with the hosts files. So opened up Notepad, ran it as Admin and then opened Hosts and at the bottom added ' 127.0.0.1 facebook.com' then saved the file. But
    facebook is still opening when I go to the page. 
    can someone tell me why  using the Hosts file isn't working?
    I did read somewhere that it might have something to do with security features on my system. FYI, I m using a trial version of Norton Anti Virus and I am running a Windows 7 machine. 
    Thanks. Any help would be appreciated. 

    Are you sure your entry was in fact saved to the hosts file?  The hosts file on my computer blocks unwanted sites.
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread. ”
    Yes
    This is a copy paste of CMD.exe. It shows what's in the host files. 
    Microsoft Windows [Version 6.1.7600]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.
    C:\Users\mehdi>cd C:\windows\system32\drivers\etc
    C:\Windows\System32\drivers\etc>dir \a-d
     Volume in drive C is Gateway
     Volume Serial Number is B291-A8C6
     Directory of C:\
    File Not Found
    C:\Windows\System32\drivers\etc>dir /a-d
     Volume in drive C is Gateway
     Volume Serial Number is B291-A8C6
     Directory of C:\Windows\System32\drivers\etc
    10/23/2010  01:06 PM               846 hosts
    06/10/2009  02:00 PM             3,683 lmhosts.sam
    06/10/2009  02:00 PM               407 networks
    06/10/2009  02:00 PM             1,358 protocol
    06/10/2009  02:00 PM            17,463 services
                   5 File(s)         23,757 bytes
                   0 Dir(s)  936,919,461,888 bytes free
    C:\Windows\System32\drivers\etc>type hosts
    # Copyright (c) 1993-2009 Microsoft Corp.
    # This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
    # This file contains the mappings of IP addresses to host names. Each
    # entry should be kept on an individual line. The IP address should
    # be placed in the first column followed by the corresponding host name.
    # The IP address and the host name should be separated by at least one
    # space.
    # Additionally, comments (such as these) may be inserted on individual
    # lines or following the machine name denoted by a '#' symbol.
    # For example:
    #      102.54.94.97     rhino.acme.com          # source server
    #       38.25.63.10     x.acme.com              # x client host
    # localhost name resolution is handled within DNS itself.
    #       127.0.0.1       localhost
    #       ::1             localhost
    127.0.0.1 facebook.com
    C:\Windows\System32\drivers\etc>

  • I accidentally screwed up my apple id when trying to change my primary email address. Password recovery options and security questions arent working either to restore

    I accidentally screwed up my apple id when trying to change my primary email address. Password recovery options and security questions arent working either to restore. Created a new appleid just to get into forums to ask a question but hesitate to sync itunes and iphone with it as i may lose all purchased music apps etc. can anyone help? i have received no email response frm apple support, it's been over 48 hours

    I have the same problem - it is maddening. I rely on this iPad for work so this is not just an annoyance! The above solutions of changing the appleid on the device or on the website do not work.
    The old email address no longer exists - I haven't used it in a year probably and I no longer have the account.  I logged into the appleid website and there is no trace of the old email address so there is nothing that can be deleted or changed there.  On the iPad there is no trace of the old email address so nothing can be deleted there either. I have updated the iPad software and the same problem comes right back.  Every 2 seconds I am asked to log in using the old non-existent email.  The device is currently useless.
    The only recent change to anything was the addition of an Apple TV device, which was set up using the correct login and password.
    Does anyone have any ideas? The iPad has been backed up to the iCloud so presumably it now won't recognize the current iCloud account? So restoring may notbe an option?

Maybe you are looking for

  • How do i print from my ipad with a netgear wndr3700

    I called Netgear and they refused to help me without charging $99 for Premium Support (more than I paid for the router). I can find no documentation to help.

  • Jdeveloper 10.1.3.2 with Oracle AS 10.1.3 : java.lang.NoSuchMethodError: or

    Hi, I develop application on Jdeveloper 10.1.3.2 and it's working when I run on OC4J in Jdeveloper. But when I deploy on Oracle Application Server 10.1.3, I got error message like this java.lang.NoSuchMethodError: oracle.adf.share.perf.StateTracker.i

  • Unplanned depreciation

    Hi All, I have posted the unplanned depreciation thru ABAA and in AW01n, i can see the unplanned depreciation with the posted amount. Now i want to reverse this posting. I am trying it thru AB08 for that asset but it says No FI document is posted and

  • Cost Based Query

    i have removed the RULE hints and tried the below query in 2 different databases both same version(10g) In one of the database query completed in 4hrs and in another database it completed in 3 days. Both databases has similar data. where i am doing w

  • Thomson Treasura - replace with Electronic Bank Statement

    Hi All, We are planning to implement EBS in our co and replace an external Software called Thomson treasura. I would like to know what sort of reports are availble through the EBS in SAP. Thomson treasura gives the ability to generate several reports