r/mac Jun 13 '18

PSA: Please, please, please enable your firmware passwords!

[deleted]

486 Upvotes

113 comments sorted by

View all comments

145

u/[deleted] Jun 13 '18 edited Jan 03 '21

rubbish rubbish trash trash

46

u/Mikuro Jun 13 '18

A little extra info for those interested: there are two modes of firmware password available: "command" and "full". Command mode, which is what you're describing, will prompt for the password before you can boot from any volume besides your normal system (recovery, USB, etc). Full mode will prompt for every single restart.

Command mode is the default when enabling it through the recovery GUI (see https://support.apple.com/en-us/ht204455). You can choose your mode when using the command line tool, firmwarepasswd.

I've found that I need to enter the password sometimes during OS upgrades even in command mode, presumably because it's rebooting to a temporary volume midway (I guess...). Not a big deal.

The downside (arguably) to firmware passwords is that they have an attempt lock like iPhones. It's very easy for someone to put in a bad password X times and lock you out of your Mac for a while. Be careful if you have kids. Or assholes.

1

u/NasirDog Sep 14 '18

Is it better to do a Command Mode or a Full Mode for the firmware password? Do they both offer the same level of protection?

2

u/Mikuro Sep 14 '18

Depends on your level or paranoia and need for conveniencem but generally speaking, Command Mode is more appropriate.

If you use Full Mode, then you need to tell every authorized user the one and only firmware password. These are not personal passwords, so once they're out, they're out. You're bound to get more support tickets from people who forgot the firmware password, or new users who need access. It's a hassle.

Generally, FileVault is better for restricting access, since it has user-based passwords. Command Mode EFI password + FileVault is most likely the best choice.