Welcome to PCForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Security Flaw in MSI Motherboard

 
   Hardware Problem Solving Community! (Home) -> MSI-Microstar RSS
Next:  SSS - anyone knows this chip brand? (ATA Flash / ..  
Author Message
Joe Hesse

External


Since: Oct 11, 2007
Posts: 6



(Msg. 1) Posted: Wed Oct 31, 2007 8:35 am
Post subject: Security Flaw in MSI Motherboard
Archived from groups: alt>comp>periphs>mainboard>msi-microstar (more info?)

Hi,

I have an MSI P35 Neo F motherboard. The AMI BIOS has been changed by MSI
so that a user password can not be set. A setup password can be set, just
no user password.

Without a user password, someone could boot from a Linux CD and access
Windows or other partitions on the hard drive. A user password is the first
line of defense against this. For unknown reasons, MSI has decided to
remove the user password feature.

Joe Hesse

 >> Stay informed about: Security Flaw in MSI Motherboard 
Back to top
Login to vote
Bill16

External


Since: Jul 11, 2003
Posts: 330



(Msg. 2) Posted: Wed Oct 31, 2007 12:19 pm
Post subject: Re: Security Flaw in MSI Motherboard [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

In article <13ih14ck095rc88.RemoveThis@corp.supernews.com>, joe_hesse.RemoveThis@actcx.com
says...
> Hi,
>
> I have an MSI P35 Neo F motherboard. The AMI BIOS has been changed by MSI
> so that a user password can not be set. A setup password can be set, just
> no user password.
>
> Without a user password, someone could boot from a Linux CD and access
> Windows or other partitions on the hard drive. A user password is the first
> line of defense against this. For unknown reasons, MSI has decided to
> remove the user password feature.
>
> Joe Hesse
>
>
>

Your user password lasts about as long as it takes somebody to open
the cover and reset your cmos. If you're worried about somebody
accessing your hard drive; encrypt it.

Bill

 >> Stay informed about: Security Flaw in MSI Motherboard 
Back to top
Login to vote
Strobe

External


Since: Dec 23, 2006
Posts: 6



(Msg. 3) Posted: Wed Oct 31, 2007 11:03 pm
Post subject: Re: Security Flaw in MSI Motherboard [Login to view extended thread Info.]
Imported from groups: per prev. post (more info?)

Back to top
Login to vote
Joe Hesse

External


Since: Oct 11, 2007
Posts: 6



(Msg. 4) Posted: Thu Nov 01, 2007 12:38 pm
Post subject: Re: Security Flaw in MSI Motherboard [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Bill" <spamtrap.TakeThisOut@tinlc.lumbercartel.com> wrote in message
news:MPG.21927528beef331298970f@localhost...
> In article <13ih14ck095rc88.TakeThisOut@corp.supernews.com>, joe_hesse.TakeThisOut@actcx.com
> says...
>> Hi,
>>
>> I have an MSI P35 Neo F motherboard. The AMI BIOS has been changed by
>> MSI
>> so that a user password can not be set. A setup password can be set,
>> just
>> no user password.
>>
>> Without a user password, someone could boot from a Linux CD and access
>> Windows or other partitions on the hard drive. A user password is the
>> first
>> line of defense against this. For unknown reasons, MSI has decided to
>> remove the user password feature.
>>
>> Joe Hesse
>>
>>
>>
>
> Your user password lasts about as long as it takes somebody to open
> the cover and reset your cmos. If you're worried about somebody
> accessing your hard drive; encrypt it.
>
> Bill

Bill,

Thank you for the reply.

I know you can open the cover and reset the cmos. However, if you secure
the cover with a lock you can tell that it has been broken into.
I only want the level of protection that prevents some curious person
putting a bootable CD or USB stick and mucking around with my computer.

I think that MSI made a bad decision by removing user passwords; after all,
you don't have to use it if it doesn't fit your need.

Regards,
Joe
 >> Stay informed about: Security Flaw in MSI Motherboard 
Back to top
Login to vote
Joe Hesse

External


Since: Oct 11, 2007
Posts: 6



(Msg. 5) Posted: Thu Nov 01, 2007 12:48 pm
Post subject: Re: Security Flaw in MSI Motherboard [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Strobe" <Strobe.TakeThisOut@nyc.Beep!Beep!.com> wrote in message
news:m4gii3h970o5cidilk9ip0aacvjdjrhabs@4ax.com...
> On Wed, 31 Oct 2007 08:35:06 -0500, "Joe Hesse" <joe_hesse.TakeThisOut@actcx.com>
> wrote:
>
>>Hi,
>>
>>I have an MSI P35 Neo F motherboard. The AMI BIOS has been changed by MSI
>>so that a user password can not be set. A setup password can be set, just
>>no user password.
>>
>>Without a user password, someone could boot from a Linux CD and access
>>Windows or other partitions on the hard drive. A user password is the
>>first
>>line of defense against this. For unknown reasons, MSI has decided to
>>remove the user password feature.
>
> That's not a problem.
> Use the password-protected set-up to allow booting ONLY from your HDD.

Thank you for the reply.

If I password the BIOS setup and allow booting only from the HDD, then I
have to alter the boot options whenever I want to boot from a CD. If I
forget to change it back my computer is vulnerable to casual users. With a
user password permanently set, its a no brainer for me. I always have to
enter the short password to start my computer and, its my personal choice to
be able to boot from a CD, especially since I try different Linux
distributions.

I think MSI made a mistake by removing this feature. After all, you don't
have to use it if it doesn't meet your computing needs.

I'm also aware of the fact that you can open the case and reset the CMOS.
If your case has a lock on it you can easily see if your case has been
opened without your permission.

Regards,
Joe
 >> Stay informed about: Security Flaw in MSI Motherboard 
Back to top
Login to vote
El Kapitano

External


Since: Sep 07, 2007
Posts: 7



(Msg. 6) Posted: Sun Nov 04, 2007 5:49 pm
Post subject: Re: Security Flaw in MSI Motherboard [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Yeah I heard your gripe the first time you posted it....

Paranoia or OCD?

Simple way is not to upgrade to the new bios unless you absolutely need some
new fix or feature.


:O)

"Joe Hesse" <joe_hesse DeleteThis @actcx.com> wrote in message
news:13ih14ck095rc88@corp.supernews.com...
> Hi,
>
> I have an MSI P35 Neo F motherboard. The AMI BIOS has been changed by MSI
> so that a user password can not be set. A setup password can be set, just
> no user password.
>
> Without a user password, someone could boot from a Linux CD and access
> Windows or other partitions on the hard drive. A user password is the
> first line of defense against this. For unknown reasons, MSI has decided
> to remove the user password feature.
>
> Joe Hesse
>
 >> Stay informed about: Security Flaw in MSI Motherboard 
Back to top
Login to vote
Joe Hesse

External


Since: Oct 11, 2007
Posts: 6



(Msg. 7) Posted: Mon Nov 05, 2007 9:46 am
Post subject: Re: Security Flaw in MSI Motherboard [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hi,

Thank you for your honest reply. I always worry about being paranoid and/or
having OCD. That is the reason I posted my comment; I wanted some feedback.

The bios that came with my motherboard did not have the ability to set user
passwords. I am hoping that MSI will "see the light" and fix it in future
bios releases.

So far you are the only one who seems to feel that this is not an issue. I
am hoping some others will reply saying I am crazy or they agree with me.

Thanks,
Joe

P.S.
I top posted since this is how you replied.

I have not received
"El Kapitano" <admin DeleteThis @crammit.com> wrote in message
news:HCnXi.16980$6v.6718@newsfe2-gui.ntli.net...
> Yeah I heard your gripe the first time you posted it....
>
> Paranoia or OCD?
>
> Simple way is not to upgrade to the new bios unless you absolutely need
> some new fix or feature.
>
>
> :O)
>
> "Joe Hesse" <joe_hesse DeleteThis @actcx.com> wrote in message
> news:13ih14ck095rc88@corp.supernews.com...
>> Hi,
>>
>> I have an MSI P35 Neo F motherboard. The AMI BIOS has been changed by
>> MSI so that a user password can not be set. A setup password can be set,
>> just no user password.
>>
>> Without a user password, someone could boot from a Linux CD and access
>> Windows or other partitions on the hard drive. A user password is the
>> first line of defense against this. For unknown reasons, MSI has decided
>> to remove the user password feature.
>>
>> Joe Hesse
>>
>
 >> Stay informed about: Security Flaw in MSI Motherboard 
Back to top
Login to vote
Harry Syme

External


Since: Aug 15, 2007
Posts: 5



(Msg. 8) Posted: Sat Nov 10, 2007 6:19 am
Post subject: Re: Security Flaw in MSI Motherboard [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Joe Hesse" <joe_hesse.DeleteThis@actcx.com> wrote in message
news:13iuem0q0obi47d@corp.supernews.com...
> Hi,
>
> Thank you for your honest reply. I always worry about being paranoid
> and/or having OCD. That is the reason I posted my comment; I wanted some
> feedback.
>
> The bios that came with my motherboard did not have the ability to set
> user passwords. I am hoping that MSI will "see the light" and fix it in
> future bios releases.
>
> So far you are the only one who seems to feel that this is not an issue.
> I am hoping some others will reply saying I am crazy or they agree with
> me.
>
> Thanks,
> Joe
>
> P.S.
> I top posted since this is how you replied.
>
> I have not received
> "El Kapitano" <admin.DeleteThis@crammit.com> wrote in message
> news:HCnXi.16980$6v.6718@newsfe2-gui.ntli.net...
>> Yeah I heard your gripe the first time you posted it....
>>
>> Paranoia or OCD?
>>
>> Simple way is not to upgrade to the new bios unless you absolutely need
>> some new fix or feature.
>>
>>
>> :O)
>>
>> "Joe Hesse" <joe_hesse.DeleteThis@actcx.com> wrote in message
>> news:13ih14ck095rc88@corp.supernews.com...
>>> Hi,
>>>
>>> I have an MSI P35 Neo F motherboard. The AMI BIOS has been changed by
>>> MSI so that a user password can not be set. A setup password can be
>>> set, just no user password.
>>>
>>> Without a user password, someone could boot from a Linux CD and access
>>> Windows or other partitions on the hard drive. A user password is the
>>> first line of defense against this. For unknown reasons, MSI has
>>> decided to remove the user password feature.
>>>
>>> Joe Hesse
>>>
>>
>
>

You are crazy!

I agree with you!
 >> Stay informed about: Security Flaw in MSI Motherboard 
Back to top
Login to vote
El Kapitano

External


Since: Sep 07, 2007
Posts: 7



(Msg. 9) Posted: Sun Nov 11, 2007 6:21 pm
Post subject: Re: Security Flaw in MSI Motherboard [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Joe Hesse" <joe_hesse DeleteThis @actcx.com> wrote in message
news:13iuem0q0obi47d@corp.supernews.com...
> Hi,
>
> Thank you for your honest reply. I always worry about being paranoid
> and/or having OCD. That is the reason I posted my comment; I wanted some
> feedback.
>
> The bios that came with my motherboard did not have the ability to set
> user passwords. I am hoping that MSI will "see the light" and fix it in
> future bios releases.
>
> So far you are the only one who seems to feel that this is not an issue.
> I am hoping some others will reply saying I am crazy or they agree with
> me.
>
> Thanks,
> Joe
>
> P.S.
> I top posted since this is how you replied.
>
> I have not received
> "El Kapitano" <admin DeleteThis @crammit.com> wrote in message
> news:HCnXi.16980$6v.6718@newsfe2-gui.ntli.net...
>> Yeah I heard your gripe the first time you posted it....
>>
>> Paranoia or OCD?
>>
>> Simple way is not to upgrade to the new bios unless you absolutely need
>> some new fix or feature.
>>
>>
>> :O)
>>
>> "Joe Hesse" <joe_hesse DeleteThis @actcx.com> wrote in message
>> news:13ih14ck095rc88@corp.supernews.com...
>>> Hi,
>>>
>>> I have an MSI P35 Neo F motherboard. The AMI BIOS has been changed by
>>> MSI so that a user password can not be set. A setup password can be
>>> set, just no user password.
>>>
>>> Without a user password, someone could boot from a Linux CD and access
>>> Windows or other partitions on the hard drive. A user password is the
>>> first line of defense against this. For unknown reasons, MSI has
>>> decided to remove the user password feature.
>>>
>>> Joe Hesse
>>>
>>
>
>
To worry about having OCD or being paranoid must surely be a sign of ones
awareness of ones tendencies toward such?

You're cuckoo mate. :O)


Regards,

Andy H
 >> Stay informed about: Security Flaw in MSI Motherboard 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Nvidia MCP2-T software, where can I get it? - I have the MSI K7N2 Delta L using the optional S-Bracket (has 2 x SPDIF's). I've installed the Nvidia nForce system drivers and I cannot get into the "NVidia nForce Control Panel" as shown on page A5 of the motherboard manual. I need to adjus...

Water-cooled 865PE + Radeon 9800 XT = rocketship . . . pul.. - The good news: even without any overclocking, this new rig is yielding 90 to 100fps at 1600x1200x32bpp with 3D programs! The bad news: after a few minutes or hours, it suddenly produces a strange, Herringbone pattern of garbage on the screen. When the..

Anyone running Operon 250s on an MSI K8T800 Master 2-FAR? - Hi - I'm currently running an FX-51 on this motherboard using the 1.1 BIOS. I see on MSI's site http://www.msi.com.tw/program/support/bios/bos/spt_bos_detail.php?UID=484&kind=3 You can get a beta 1.35 to support Opteron 250's. But this came out in J...

A64 3500, Neo2, 1GB PC4000 & overclocking - Newbie questio.. - Since it's a good idea to actually have an idea of what I'm doing, I've decided to ask for help with some specific overclocking problems I've encountered. The ram I have is two sticks of 512MB PC4000 rated at 2.5-3-3. I know that staying synchronous wit...

Onboard RAID controller died :( - Hi, after being a bit flaky for a while it would appear that the onboard RAID controller on my MSI KT3-Ultra has finally given up the ghost. I can't get into BIOS or change the Boot order as I'm stuck in a "No Array is defined" - create arr...
   Hardware Problem Solving Community! (Home) -> MSI-Microstar All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]