Clear Mac Os X 10.10 “Firmware Password”

Clear Mac Os X 10.10 “Firmware Password”

Clear Mac Os X 10.10 “Firmware Password”
How to remove the firmware countersign on 2011-2020 Macs + New way for 2018-2020 T2 Macs!

You can at present remove the firmware password (+ erase all data) on a T2 Mac without Apple Support if you forgot it.

In this article, I volition go over the history of the firmware password on Intel Mac computers. Subsequently that, I will evidence you a new manner how to remove the firmware password (and erase your data) on a T2 Mac from 2018-2020.
(Scroll to section 6).

NOTE: This information is but for 2006-2020 Intel Mac computers. Apple Silicon M1 Mac Devices practice not take a firmware countersign.

I will also get over my recommendations on how yous can protect your data at the cease of this article.

I will answer the following questions.

  1. What does setting a firmware countersign on a Mac do?
  2. What are the differences in firmware passwords from the following years – 2006-2010, 2011-2017 & 2018-2020?
  3. How to yous ready the firmware password in recovery.
  4. How to Enable & Disable Firmware Password in macOS.
  5. What can you lot do if you forget the firmware password?
  6. How to remove the firmware countersign with Apple Support.
  7. Removing the firmware password on a T2 Mac with Apple Configurator 2.
  8. How long was this new way possible? Does anyone at AppleCare know about this?
  9. What does this mean for education, small & large companies, home users, computer recyclers, and criminals?
  10. What does Apple recall about this?
  11. How tin can I protect my Data on an Intel and M1 Mac?

1. What does setting a firmware countersign on a Mac do?

The firmware countersign was designed to protect your Mac. This mode protects against someone who wants to get your data. They can’t boot into target disk fashion or recovery to access your files.

Long story short, if your Mac lands in the wrong hands and you do Non have the following items enabled below, all your data is at risk!.

  1. Firmware Countersign
  2. FileVault ii Encryption
  3. Activation Lock / Find My Mac

A person could admission your data via Target disk way or macOS Recovery, even if they do not know your user password!

When you lot set a firmware password, users who don’t have the password can’t start up from any disk other than the designated startup disk.

https://back up.apple tree.com/en-us/HT204455

The Apple article below details different startup modes.

https://support.apple.com/en-gb/HT201255

If you enable the firmware password, the following startup items are disabled.

  1. Target Deejay Manner
    – (T)
  2. Netboot
    (N) – (Remember Netboot?)
  3. Single User Mode
    – (Command S)
  4. Verbose Way
    – (Command V)
  5. Squirt CD-ROM or DVD
    – (Eject Key)
  6. Rubber Mode
    – (Shift Central)
  7. Reset PRAM
    – (Option-Control-P-R)
  8. Hardware Diagnostics
    – (D)
Read:  Flash Att Firmware to Sprint Note 5

The following startup options will work, but you volition be prompted for the firmware password.

  1. Recovery Manner
    – (Control R)
  2. Internet Recovery
    – (Command Selection R
    or
    Command Choice Shift R)

If you have the firmware password enabled and you hear someone say “I reset the PRAM” …. NOPE!!!

ii. What are the differences in firmware passwords from the following years – (2006-2010), (2011-2017) & (2018-2020)?

  1. (2006-2010) – The firmware password could exist removed by removing the battery, 1 stick of ram, and resetting the PRAM three times.
  2. (2011-2017) Apple tree inverse this when they soldered the memory to the logic board. The only style to remove the firmware password was to contact Apple tree.
  3. (2018-2020) Apple added the T2 security fleck. The chip runs an operating system called BridgeOS.
    This OS software tin now exist re-installed or updated using a 2nd Mac and Apple Configurator 2.
    Y’all now need to be an admin user that has a SecureToken to access the Startup Security Utility menu to gear up and remove the firmware password.

3. How do you set the firmware countersign?

The firmware countersign tin be set in three different means.

https://support.apple.com/en-us/HT204455

  1. Enable from macOS Recovery.
  1. Start up from macOS Recovery.
  2. When the utilities window appears, click Utilities in the menu bar, so choose Startup Security Utility or Firmware Password Utility.
  3. Click Turn On Firmware Countersign.
  4. Enter a firmware countersign in the fields provided, then click Set Password.Recollect this password.
  5. Quit the utility, then choose Apple tree carte du jour > Restart.

two.
Use the
firmwarepasswd
binary


sudo firmwarepasswd -setpasswd

3.
Plow on “Detect My” through iCloud, which enables the firmware password & Activation Lock.

4. How to Enable & Disable Firmware Password in macOS?

You tin enable and disable the firmware password within macOS using terminal.app

  • one.
    sudo firmwarepasswd -setpasswd
    = Prepare a new password
  • 2.
    sudo firmwarepasswd -bank check
    = Bank check whether a password is fix
  • three.
    sudo firmwarepasswd -verify
    = Verify your password
  • 4.
    sudo firmwarepasswd -delete
    = Disable the password

5. What can y’all practise if you forget the frmware countersign?

Y’all will need to contact Apple. Apple will verify proof of ownership and also ask to verify your identity.

Read:  Moto G4 Plus Android 6.0 Stock Firmware

Let’due south say a person sold you a Mac with a firmware countersign on craigslist. Sometime later yous need to enter macOS recovery, only to find the firmware lock. Y’all are out of luck if you have 2011-2017 Mac. Yous will not exist able to detect the previous owner and you do non have proof of buying.

6. How to remove the firmware password with Apple Support.

If you have proof of ownership, Apple tree can remove the firmware countersign and retain your data for Mac Devices from 2011-2020. They will walk you through a procedure (Shift-Control-Option-Command-S) that will show you a code that you can give the Apple support agent. The agent will utilise that code to send you a file so y’all tin can create a USB kicking disk that will remove the firmware countersign.

You can take a wait at this great commodity for a super deep swoop into the firmware password setup. >
https://reverse.put.every bit/2016/06/25/apple-efi-firmware-passwords-and-the-scbo-myth/

7. Removing the firmware countersign on a T2 Mac with Apple Configurator 2.

Sad that you had to scroll this far to get to the signal of this commodity. With all the talk about how the firmware password option was removed from M1 Mac Devices, I wanted to explore a little history first.

If you need to remove the Firmware password from a T2 Mac, all you lot need to practise is Restore BridgeOS with a 2nd Mac and Apple Configurator 2.

What does an Apple Configurator ii “Restore” practise on a T2 Mac?

  1. Erase the entire SSD (Macintosh HD & macOS Recovery)
  2. Clear Saved NVRAM Settings i.e stored WIFI
  3. Reset whatever previous Secure Boot Settings back to default
  4. Reinstall BridgeOS with the latest version available from Apple.
  5. Remove the Firmware Password, if it was previously set.

Note!!!! This only works with a “RESTORE FULL ERASE” not a “Revive”. A revive volition retain your data and only reinstall BridgeOS. The choice will non remove your firmware password.

Yous can follow my instructions hither >
https://mrmacintosh.com/how-to-restore-bridgeos-on-a-t2-mac-how-to-put-a-mac-into-dfu-mode/

This procedure is very shut to the new M1 Apple tree Silicon Mac “Erase Mac Process” The difference is that macOS Recovery is still bachelor after the process and then you tin can easily reinstall macOS.

8. How long was this new way possible? Does AppleCare even know about this?

I am always testing new ways to interruption and fix macOS. When I showtime confirmed that this new way worked, I was pretty surprised to say the least.

Read:  How Do I Update My Xfinity Router's Firmware

To find out, I tested with Apple Configurator two version 2.7.1 from 2019.

Yup, worked

It is very possible that AC2 was removing the firmware password during the BridgeOS restore since the very beginning.

After all this fourth dimension, did AppleCare fifty-fifty know about this choice? Apple’s own instructions only refer to the steps to contact CSS support to remove the password via firmware hash / USB drive.

9. What does this mean for education, small & large companies, home users, computer recyclers, and criminals?

Let’s go over a few situations.

This new process does NOT disable or remove Activation Lock.

If you use the firmware countersign to protect your data?
– Technically you are fine because the AC2 Restore process will remove the firmware password & erase all of your data.

If you are a small business concern or education institution that is
relying on the firmware password

but does not have Activation Lock enabled. – You are most probable trying to prevent students or employees from stealing the Mac then erasing your configuration and reinstalling macOS. The other trouble (unlike iOS) a person tin can bypass the Mobile device management screen. In this case, the Mac is long gone.

If you are a computer reseller or recycler.
This is Neat news for you. Yous can at present wipe the firmware countersign and reinstall macOS.

10. What does Apple think nearly this?

I reached out to Apple and asked them. The response was that this is expected.

Apple recommends enabling Activation Lock on Macs with the T2 security chip (2018-2020)

11. How tin can I protect my Data on an Intel and M1 Mac?

I agree with Apple’s recommendation, enable Activation Lock.

Additionally, you should also enable FileVault 2.

Enabling FileVault on a T2 Mac with macOS Catalina or newer will foreclose an unwanted user from accessing your information in recovery.

If you didn’t plough on a firmware password and did not enable FileVault Encryption, your information is Wide open in macOS recovery. One interesting note, if FV2 is non enabled you volition nevertheless be prompted for a countersign in Target Disk Style.

Clear Mac Os X 10.10 “Firmware Password”

Check Also

Can I Install Sturtle Beach Firmware Update on a Tablet

Can I Install Sturtle Beach Firmware Update on a Tablet Blog #1 I’m hoping someone …