majestic0110 187 Nearly a Posting Virtuoso

(Sorry thread title should read BUG not BUT lol )Hi all, I am not sure if this is the right forum for this (so please move if not) but I was tinkering with a Toshiba notebook earlier that has a power up (user) password. Without this password it is not possible to gain access to the OS on the machine. Now, this notebook has XP installed and I needed to enter safe mode, so I powered up the machine, entered the Toshiba user (BIOS, under the TOshiba Assist hardware configuration software) password and held F8 for safe mode. Upon entering the log on screen to XP, I typed in the relevant administrator password and all was fine. However, after I shut down the machine and restarted in I noticed that the machine entered XP (non safe mode) WITHOUT the need for the BIOS password. (I didnt accidentally turn the BIOS password utility off, as that would have required the BIOS password itself). So, I shut down, waited a few seconds, powered up and again no BIOS password prompt........WHen logged in to XP I opened up the hardware configuration panel and lo and behold the BIOS password had been disabled!!! Strange ? Obviously a bug in there somewhere.......Needless to say, the BIOS password was reactivated (requiring entering the original p/w). So the upshot of all this is that the BIOS password is obviously not that secure (even though I needed to enter it once to enter safe mode)! What are your thoughts on this ?

Dani AI

Generated

— a firmware "power-on" password that appears to disable itself after a single successful entry usually points to one of a few causes: a vendor-supplied Windows utility changing firmware settings, a firmware bug, or NVRAM/retention problems. It is not conclusive evidence of an OS compromise, but it does show that relying on that password alone for protecting data or preventing access is risky.

Diagnostic checklist to run (safe, non-destructive):

  • Reproduce the issue in a controlled way: set a known BIOS password, cold-boot and confirm the prompt, then power-cycle again to see whether the prompt still appears.
  • Disable or uninstall any vendor configuration utility in Windows (the software that can write settings back to firmware) and repeat the test.
  • Record the BIOS/firmware version and model so you can check release notes; update the firmware and any vendor utilities to the latest supported versions.
  • Inspect Windows Event Viewer for entries from vendor utilities and look for any logs that indicate a firmware change was made from the running OS.

Practical security notes: firmware passwords are a deterrent but not a substitute for encryption. For real protection of data on a laptop use full-disk encryption (for Windows devices, BitLocker is Microsofts built-in option) and keep firmware and vendor utilities updated. Background on BIOS-password limitations and attack vectors is covered here: . For disk-level protection see: BitLocker overview. If the behavior persists, contact the vendor support with your model and BIOS version so they can investigate a possible firmware bug.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.