Whether you've forgotten your computer password or a used laptop you bought online with a locked BIOS, hacking your machine to find the password is fairly easy. If physical access is unrestricted, the process is similar to replacing a watch battery. If tearing your machine apart takes you out of your comfort zone or is otherwise impractical, there's also the option of software.
Most laptop vendors store a checksum of your password in the machine’s FlashROM – a chip that resides on your computer’s motherboard. When an incorrect password is entered three times, a “System Disabled” message appears along with what appears to be an error code. This “standard” error code is actually a salted checksum of the BIOS password. Each BIOS vendor has their own salt, but the process for cracking the password is basically the same and involves less than 100 lines of Python.
Security blogger Dogbert provides a library of scripts that crack BIOS passwords for most laptop vendors. Anyone running them will need Python 2.6 or can run the packaged Windows. The scripts are essentially brute force dictionary attacks that try to find a hash using the vendor's master salt or serial number. This hash is compared to the checksum you get after running the wrong passwords in your motherboard's BIOS. When a match is found, it is printed to the console.
Some vendors have taken it upon themselves to beef up their security. Some FSI laptop models will hold the checksum until three separate passwords – for example, first “Show The Password” and then “@skD*63 hda@1iA $Ml1a23”. Other vendors, in turn, require pressing certain keys (F2 / F12) or a combination of keys at the right time.
Hacking the BIOS password can give an attacker low-level access to the machine. For example, once they enter the BIOS, they could change the boot order to favor booting from a USB drive. From there, they could boot an operating system and access the machine's hard drive as if it were an external drive. They could also run analysis tools on the files, looking for passwords or personal information. Finally, most importantly, they could make a copy of the entire contents of the drive and take it to a private lab for further analysis.


