Home
Posted By: jaybass EFICHECK - 05/14/23 04:14 PM
Yesterday a window appeared saying eficheck dump which I don't understand. I duck ducked it and it suggested that an OS reinstall would fix it. There was something else about having a firmware password which I did. Booting into recovery mode a padlock appeared, something
I wasn't expecting but eventually realized that I had to enter my firmware password to proceed to reinstalling my OS. After that everything was back to normal.

Question, what are the pros and cons of having/not having a firmware password and do I need one?

jaybass
Posted By: ryck Re: EFICHECK - 05/15/23 06:14 PM
Originally Posted by jaybass
Question, what are the pros and cons of having/not having a firmware password and do I need one?
I'm glad you asked the question, and I hope someone has a good answer, as I was wondering the same thing.

I always thought a firmware password provided a level of additional security if your machine was stolen because booting from an external drive it would allow the thief to access the data without an Administrator password. Now I'm not sure. I recently had to boot my iMac from an external drive but couldn't access my machine without entering an Administrator password.
Posted By: jaybass Re: EFICHECK - 05/15/23 08:01 PM
Hi Ryck,
Additional security, yes you would think so but from what I read, if you have file vault "on" that should be good enough. I could be wrong though.

I thought someone would have responded before now...hopefully someone will.

jaybass
Posted By: artie505 Re: EFICHECK - 05/15/23 08:28 PM
I'm sure that joemike will respond sooner or later with a far more "educational" contribution, but I'll contribute what I can.

A firmware password is more or less "ultimate security..." no one can access a Mac with a firmware password in any way shape or form other than by entering that password, so it's particularly useful if you Mac is vulnerable to theft or access by others.

A firmware password is so secure, that if you forget yours, you've got to bring your Mac to a genius bar together with your purchase receipt to gain access to it. (I.e., a stolen Mac with a firmware password is essentially a brick.)
Posted By: joemikeb Re: EFICHECK - 05/15/23 09:37 PM
From what I have read the firmware password is a usefull tool for computer lab admins and corporate IT departments for preventing user's from installing alternate OS versions, or booting from external disk drives. Apple documents how to set, reset firmware passwords here and is unique in that you can take your computer, the purchase receipt, and a legal photo ID to Apple and they can reset it using a back door. As I see it, the existence of a back door reset makes the security of a firmware password as possibly the weakest link in Apple's security chain. Fortunately there are much stronger protections further down the chain.

That said, if I were the administrator of a computer lab or head of a corporate IT department I would definitely set the firmware password on all my computers to reduce the opportunity or data loss or corruption. As a software design engineer in the same type of environment, I would probably reset the password to prevent some IT drone from messing with my carefully curated system. (NOTE: If you say I said or did that, I have no idea what, who, when, or where you are talking about. wink ) As an individual user on my own computer in a reasonably safe environment, I wouldn't mess with setting it, unless as in the situation described it becomes necessary.
Posted By: joemikeb Re: EFICHECK - 05/17/23 03:26 PM
While we are on the general subject of security, the eclectic Light Company's FREEWARE app Silent Knight that on demand or automatically scans and reports the status of Apple's various security elements including the EFI status and if necessary will download and install the latest version. In my opinion, an equally important concomitant of Silent Knight is the very informative, 25 page, Silent Knight reference manual that is included in the download and contains clear explanations of each of Apple's platform security features.

I highly recommend it.

NOTE: I have no relationship, pecuniary or otherwise, with The Eclectic light company other than that of satisfied user and fan.
Posted By: ryck Re: EFICHECK - 05/19/23 07:25 PM
Originally Posted by joemikeb
While we are on the general subject of security, the eclectic Light Company's FREEWARE app Silent Knight that on demand or automatically scans and reports the status of Apple's various security elements including the EFI status and if necessary will download and install the latest version.
I've taken a peek and this is definitely a very interesting piece of software. However, I'm a believer in "simpler is better" so my question would be: "If a user installed Silent Knight, what can they now do without?".Is there some 'security' software that can now be thrown away to avoid complications that may arise from duplicated efforts?
Posted By: Ira L Re: EFICHECK - 05/20/23 04:05 PM
Originally Posted by ryck
Originally Posted by joemikeb
While we are on the general subject of security, the eclectic Light Company's FREEWARE app Silent Knight that on demand or automatically scans and reports the status of Apple's various security elements including the EFI status and if necessary will download and install the latest version.
I've taken a peek and this is definitely a very interesting piece of software. However, I'm a believer in "simpler is better" so my question would be: "If a user installed Silent Knight, what can they now do without?".Is there some 'security' software that can now be thrown away to avoid complications that may arise from duplicated efforts?

I don't think you would be able to throw away anything, other than a level of worry. wink

If you leave your Mac (desktop or laptop) powered on (sleeping is OK) all the time you will automatically receive Apple's latest security updates. In my case, the laptop is not always running, so I use Silent Knight to check to see if the laptop has the latest security updates; if not, Silent Knight can download them for you.
Posted By: joemikeb Re: EFICHECK - 05/20/23 04:22 PM
EFICheck is useful in keeping you aware of the total System Integrity Platform status and offering configuration suggestions and help in setting. It doesn’t do anything that you could not do with half a dozen other apps and a dozen manuals, it merely consolidates everything into one app.
© FineTunedMac