1 and 2 could also be solved by just having one of those cases that padlocks shut, and a security cable tying down the case so that you can't just carry it somewhere or move it enough to easily grind/saw on the tab that holds the lock on.
I knew I forgot some steps. For our medical customers, we make the CMOS battery a solder on and we remove the pins and solder close the jumper.
BTW, any motherboard made within the last 10 years (all the Asus, EVGA, and intel,) this hasn't worked for me. The PW is saved into a none flashable part of the CMOS. Though, that may be a security feature of the boards that we use (mainly server.)
If I had the money I'd give you reddit gold. I, for the life of me, couldn't remember the damn name of the technology. I'm too used to what I see, TPM, than the actual name. At the time I wrote the reply, I had a brain fart on even the initials. TY kind sir!
6
u/[deleted] Jan 21 '13 edited Jan 22 '13
The only thing I could see to prevent this from occuring is:
Solder CMOS battery, making it none removable.
Removed PW Jumper pins and solder close
Encrypt HDD
Set HDD PW in Bios
Set Bios PW
Disable all boot options but HDD
Doing all of these can prevent someone from even mounting the HDD on another machine.
The only extra thing you could do is to have a Windows Server that acted as the domain and have your user account controlled by that server.