|
Physical access is the problem. Give me a system with passworded windows logon and I can disable the pw in some minutes (remove BIOS pw if existant, boot from boot-cd and manipulate registry).
If you don't want this to happen you need some sort of encryption on the system, preferrably boot encryption (truecrypt 5.x does this).
|
And IIRC even THAT is circumventable by turning a bottle of canned air upside down, turning the computer off and immediately spraying the RAM... although that might be hard drive encryption.
It's the nature of security, unfortunately. The only unbreakable security measures have the inconvenient side-effect of also locking out the people that are SUPPOSED to use it.
Jam it back in, in the dark.