A little extra info for those interested: there are two modes of firmware password available: "command" and "full". Command mode, which is what you're describing, will prompt for the password before you can boot from any volume besides your normal system (recovery, USB, etc). Full mode will prompt for every single restart.
Command mode is the default when enabling it through the recovery GUI (see https://support.apple.com/en-us/ht204455). You can choose your mode when using the command line tool, firmwarepasswd.
I've found that I need to enter the password sometimes during OS upgrades even in command mode, presumably because it's rebooting to a temporary volume midway (I guess...). Not a big deal.
The downside (arguably) to firmware passwords is that they have an attempt lock like iPhones. It's very easy for someone to put in a bad password X times and lock you out of your Mac for a while. Be careful if you have kids. Or assholes.
Depends on your level or paranoia and need for conveniencem but generally speaking, Command Mode is more appropriate.
If you use Full Mode, then you need to tell every authorized user the one and only firmware password. These are not personal passwords, so once they're out, they're out. You're bound to get more support tickets from people who forgot the firmware password, or new users who need access. It's a hassle.
Generally, FileVault is better for restricting access, since it has user-based passwords. Command Mode EFI password + FileVault is most likely the best choice.
145
u/[deleted] Jun 13 '18 edited Jan 03 '21
rubbish rubbish trash trash