Donald Duff-McCracken
Technical Services Manager
Mapping, Analysis & Design
Faculty of Environment
University of Waterloo
(519) 888-4567 x32151

From: Keith Peck <kdpeck at<mailto:kdpeck at>>
Date: Monday, 28 January, 2013 4:06 PM
To: MacTUG <mactug at<mailto:mactug at>=
Subject: [MacTUG] Preventing unauthorized OSX "Recovery"

Is there a way to prevent a user from sitting down and accessing the Recove=
ry Options if they were to boot a machine running OSX 10.8 or 10.7?

Say someone holds down the 'ALT' key at system boot and decides to select t=
he Recovery Option, then uses the Disk Utility to wipe the hard drive, or a=
 re-install to give themselves admin access to the machine.

I=92m hoping for something like a requirement to enter a password before an=
ything under the =91Recovery=92 selection can be used when the =91ALT=92 ke=
y is held at boot.

Keith Peck
Client Services, Information Systems and Technology
University of Waterloo, Waterloo, Ontario, Canada, N2L 3G1.
MC 2020, (519) 888-4567 x.37770
kdpeck at<mailto:kdpeck at>

<div>To elaborate on Dani's comments.</div>
<div>This is not some great site that I have bookmarked or anything, but th=
is page explains it reasonably well</div>
<div><a href=3D"
<div>There are some ways to do it without booting from the recover partitio=
n (or a system dvd) but I would likely do it the official way the first tim=
e at least.</div>
<div>In the older macs, the firmware password was not perfect in the securi=
ty in that any simple change in the mac's hardware (like pulling out some o=
f the RAM) was enough to turn off the firmware. I think the reasoning was t=
hat if you could 'break in' to the
 mac enough to change the hardware, then clearly you were an admin type and=
 you should be able to turn off the firmware password. This line of reasoni=
ng was quasi-acceptable if all you had were Mac Towers, which could be lock=
ed to prohibit access, but there
 were a lot of macs such as a lot of iMacs and Mac Minis where it was reall=
y easy to change the ram configuration.</div>
<div>From what I understand (e.g.&nbsp;<a href=3D"
m/2012/02/how-to-set-the-firmware-password-in-mac-os-x">http://www.chriswri=</a>/ ) ever si=
nce 2011 overruling the firmware password
 is not so easy and that it generally requires an Apple technician to do. D=
ani, or anyone else, is this the case that disabling an unknown firmware pa=
ssword requires a trip over to see Dale Kentner? ;-)</div>
<p class=3D"MsoNormal">Is there a way to prevent a user from sitting down a=
nd accessing the Recovery Options if they were to boot a machine running OS=
X 10.8 or 10.7?<o:p></o:p></p>
<p class=3D"MsoNormal">Say someone holds down the 'ALT' key at system boot =
and decides to select the Recovery Option, then uses the Disk Utility to wi=
pe the hard drive, or a re-install to give themselves admin access to the m=
<p class=3D"MsoNormal">I=92m hoping for something like a requirement to ent=
er a password before anything under the =91Recovery=92 selection can be use=
d when the =91ALT=92 key is held at boot.<o:p></o:p></p>
<p class=3D"MsoNormal"><span style=3D"color:#1F497D;mso-fareast-language:EN=
-CA">Keith Peck<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"color:#1F497D;mso-fareast-language:EN=
-CA">Client Services, Information Systems and Technology<o:p></o:p></span><=
<p class=3D"MsoNormal"><span style=3D"color:#1F497D;mso-fareast-language:EN=
-CA">University of Waterloo, Waterloo, Ontario, Canada, N2L 3G1.<o:p></o:p>=
<p class=3D"MsoNormal"><span style=3D"color:#1F497D;mso-fareast-language:EN=
-CA">MC 2020, (519) 888-4567 x.37770<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"color:#1F497D;mso-fareast-language:EN=
-CA"><a href=3D"mailto:kdpeck at"><span style=3D"color:blue">kdpe=
ck at</span></a><o:p></o:p></span></p>
