Hacker News new | ask | show | jobs
by afhsfsfdsss88 4476 days ago
This is what came to me first. I have unrestricted physical access?

I probably own the machine. If the data on the storage is not encrypted, I own that too.

If I don't want to disassemble anything, I just plug in a liveUSB and it's all mine.

If the BIOS has USB/CD boot disabled? I pull the CMOS battery.

If that fails? The google probably knows the BIOS reset sequence for your board and soon so will I.

=======================================================================

Physical security is important too and FDE is not optional. [Even if you have nothing to hide]

1 comments

The CMOS battery often has nothing to do with BIOS settings, on many modern laptops it's stored in the BIOS flash memory, with no such reset sequence available.

If properly secured, physical hacking is not as easy as it used to be.

NVRAM can be overwritten with a factory fresh BIOS image....
Yes, but then you're in the realm of interfacing directly with the hardware to reflash the chip, somewhat upping the difficulty of this hack.