cross-posted from: https://infosec.pub/post/51950708

I bought a 2nd-hand HP Probook 645 g1. The BIOS is passworded. So naturally I unplug, pull out the battery, and also disconnect the realtime clock (RTC) battery. Press the power on button to help drain any capacitors and wait a bit. This procedure is so mainstream I do it without looking anything up. After re-juicing, booting gives some kind of error about a bad BIOS config, which I find a bit rude but then fair enough that it advises me to configure the BIOS.

A BIOS password is /still/ demanded. Fuck me. HP stores BIOS passwords in a TPM so even when the BIOS is wiped out, the password persists. Then according to this page, you are extra fucked if you reset the BIOS clock without having the password:

“don’t try removing the rtc battery. It won’t remove the password, but it will reset the clock - as smc files are time coded, a large disparity between the system clock and the time encoded in the smc will cause it to fail.”

Fuck me! This means even if HP were willing to help (which I doubt), the reset file they send me won’t work after I have reset the clock.

When I get the password wrong 3 times, I get no 8-digit “system disabled code”. I get nothing.

So it seems the BIOS chip must be de-fucking-soldered from the motherboard and flashed using an external flasher. Anyone find this infuriating? These are the sources for that info:

Disgusting to see that the advice on HP’s site for resetting the BIOS p/w on /some/ models is to remove the battery (the same advice that fucks people who have different models): https://web.archive.org/web/20170212194834/http://h30434.www3.hp.com/t5/Notebook-Video-Display-and-Touch/Reset-BIOS-Password-EliteBook-8540w/td-p/927153

On some HP laptops, there is a possibility to boot an HP Recovery Tool. I have yet to try them but it seems like I’m fucked because there are people whose only way forward is to desolder and flash externally.

Question: why couldn’t HP send an SMC.bin file that is based on a reset clock? Would it get bricked if I then later update the clock to be current?

Update

Oh wtf… It’s actually a Schrodinger’s cat shitshow. This is in the manual:

“Clear BIOS Passwords on RTC Battery Removal has 2 options:

  • enable
  • disable

When Disable is selected, the removal of the RTC battery WILL NOT clear the BIOS Administrator Password (BAP) and Power-on Password (POP). When Enable is selected, the removal of the RTC battery WILL clear the BIOS Administrator Password (BAP) and Power-on Password (POP). If Cover Removal Sensor is enabled and select to Administrator password or Administrator credential, then the RTC Battery Removal policy cannot be enabled and is also greyed out in F10. If the RTC Battery Removal policy is enabled, then Cover Removal Sensor Administrator password and Administrator credential cannot be enabled and is also greyed out in F10.”

So removing the RTC battery is a way to reset the password but only if a boolean IN the BIOS has a certain state. But if you lack the password in the 1st place, you cannot see it! WTF… designed by fucking morons! So if you cannot reach the setting to see the state, you cannot know in advance whether disconnecting the battery will clear the pw or fuck you over by clearing the clock and still denying access. Users are essentially forced to play roulette.

Motherfuckers!