Ads by TechWords

See your link here
Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Macintosh
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
 

Open Firmware Security for Mac Workstations

August 12, 2005 12:00 PM ET

Computerworld - When Apple Computer Inc. introduced Open Firmware with the first G3 Macintosh computers, it was big news because it allowed Apple to easily modify system information previously stored in ROM. This meant that revisions made to ROM code after a computer had been manufactured and sold could still be applied to that computer. It also meant that Apple didn't need to patch the operating system to work around older ROM data. It wasn't until Apple introduced the iMac in 1998 that Open Firmware gained common use. The iMac introduced what's called New World ROM architecture, where some of the data previously kept in ROM could now be stored on in a file on a computer's start-up disk (which is even easier to update than firmware data stored on the motherboard).
I could go into many more details about Open Firmware besides its relevance to security, but I'll settle for one main point: Open Firmware is accessed immediately after the Mac's power-on self-tests and before any operating system loads from any device. Calls to it are used to boot with most start-up key combinations, including booting from CD, from a default NetBoot image, through target disk mode (where the computer's hard drive mounts as a firewire drive on another computer) or the start-up manager. As you have already guessed, most of these special start-up modes offer a way for a user to gain full access to a computer's hard drive.
If you can boot from a Mac OS 9 disk, then you have full access to the hard drive, regardless of the permissions assigned to files and folders. If you boot from a Mac OS X CD, you can use the Reset Password command to change the administrator and root passwords for the workstation. If you boot into target disk mode, you can use another computer to copy items from the hard drive. If you boot from an alternate disk (such as a CD, DVD or hard drive), you can run several versions of Unix or Linux and access any data you choose on the internal hard drive of the computer. CDs or DVDs, iPods and portable hard drives are all small, easy to carry, require little or no cables and can be unobtrusively attached to a workstation. And all of them can be bootable, easily allowing a user to circumvent any security measures and permissions you have configured on a workstation.

Open Firmware Security Modes
Open Firmware allows you to set a password for the workstation and to choose one



Additional Resources

POLL RESULTS
Accelerate your knowledge of the IT world you inhabit by viewing the results of a series of polls taken by your IT peers. These polls of 100+ IT professionals each are available for full viewing. They cover key topics such as virtualization, processor performance, green IT, cloud computing and many others. Be a part of the buzz.
WHITE PAPER
Technology is complex. Keeping it running productively shouldn't be. To that end, you want to minimize the number of solutions needed in-house to simplify operations, maintenance, and support. Kodak offers a best-practices model. One company provides support for both scanner and software, for fast problem resolution without vendor finger-pointing. Download now!
WHITE PAPER
Utilizing demand intelligence improves the precision of pricing, product assortments, channel/store placement, and promotion, which are all essential for sustainable revenue management performance. Learn more, download this free whitepaper today.

White Papers & Webcasts

2009 Gartner Magic Quadrant Report
Truly understand your options for WAN Optimization Controllers...  

Strategic ECM Webinar
Learn what new strategic business benefits can be realized through ECM!...

Tech Horizons: ASG's metaCMDB, The Technology That Rocks
Improved business productivity often requires more efficient IT and more efficient IT cannot be achieved without a better understanding of the way business...  

Managing And Protecting Your Ever Increasing Mobile Assets
Learn best practices for desktop and application virtualization, computer security, and computer life-cycle management....

The Vector Approach to Data Center Power Planning
This white paper describes an approach that considers the major milestones and thresholds in data center power requirements-and how planners should adjust their...  

5 Architecture Issues that Impact BES performance
This Live webinar will identify critical log file errors, performance counters, and configurations to pay close attention to when optimizing BES server performance....

Yankee Group Mobile WAN Optimization Report
Mobile work continues to evolve. Learn how to keep up with the demands of your organization's mobile workforce....  

Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....

Mitigating Litigation Risk with Email Management Tools
Does your company have an email retention policy that protects it when litigation occurs? IDC discusses effective email retention policies and the role...  

The Value of Real SaaS at Workday
Cost savings, speed to value, and innovation brought to the enterprise by Workday's software-as-a-service solutions for HR and Payroll....