# Is it really this easy to circumvent a MacBook passord?

**URL:** <https://boards.straightdope.com/t/is-it-really-this-easy-to-circumvent-a-macbook-passord/964724>\
**Category:** Factual Questions\
**Created:** [May 20, 2022, 12:12am UTC](https://boards.straightdope.com/t/is-it-really-this-easy-to-circumvent-a-macbook-passord/964724 "2022-05-20T00:12:47Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Danger\_Man](https://avatars.discourse-cdn.com/v4/letter/d/6de8d8/32.png) [@Danger\_Man](https://boards.straightdope.com/u/Danger_Man)\
**Post date:** [May 20, 2022, 12:12am UTC](https://boards.straightdope.com/t/is-it-really-this-easy-to-circumvent-a-macbook-passord/964724/1 "2022-05-20T00:12:47Z")

</div>

I forgot the password for my new m1 MacBook Pro using [If you can't reset your Mac login password - Apple Support](https://support.apple.com/en-us/HT212190) . Specifically the directions under “Use the Reset Password assistant”.

I was able to select a new password and log on. Is it really this easy? What is the point in having a password if someone can just reset it like this?

---

<div class="post-metadata">

**Author:** ![Terminus\_Est](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/terminus_est/32/3087_2.png) [@Terminus\_Est](https://boards.straightdope.com/u/Terminus_Est)\
**Post date:** [May 20, 2022, 12:43am UTC](https://boards.straightdope.com/t/is-it-really-this-easy-to-circumvent-a-macbook-passord/964724/2 "2022-05-20T00:43:35Z")

</div>

Before getting to the Reset Password Assistant, you had to go through some extra steps to verify your identity, including two-factor authentication. You did set up two-factor authentication, didn’t you?

---

<div class="post-metadata">

**Author:** ![Stranger\_On\_A\_Train](https://avatars.discourse-cdn.com/v4/letter/s/13edae/32.png) [@Stranger\_On\_A\_Train](https://boards.straightdope.com/u/Stranger_On_A_Train)\
**Post date:** [May 20, 2022, 1:07am UTC](https://boards.straightdope.com/t/is-it-really-this-easy-to-circumvent-a-macbook-passord/964724/3 "2022-05-20T01:07:16Z")

</div>

Of course, what you should really do is set up a separate administrative account with superuser privileges that installs all software and system configurations, and a normal user account that does not have such access because it is actually trivially easy to do any number of things with root/admin access. Then you could log into the admin account and reset your user password as necessary instead of relying on Apple and their two-factor authentication scheme which can also be broken with some modest effort.

Stranger

---

<div class="post-metadata">

**Author:** ![beowulff](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/beowulff/32/542_2.png) [@beowulff](https://boards.straightdope.com/u/beowulff)\
**Post date:** [May 20, 2022, 1:50am UTC](https://boards.straightdope.com/t/is-it-really-this-easy-to-circumvent-a-macbook-passord/964724/4 "2022-05-20T01:50:49Z")

</div>

Note that doing this _ **DOES NOT** _ recover any passwords stored in the Keychain, so most times, this is not what the user wants to do.  
Besides, if one is not using File Vault, it isn’t even necessary to have _ **any** _ password to get access to any user’s files…

---

<div class="post-metadata">

**Author:** ![Danger\_Man](https://avatars.discourse-cdn.com/v4/letter/d/6de8d8/32.png) [@Danger\_Man](https://boards.straightdope.com/u/Danger_Man)\
**Post date:** [May 20, 2022, 5:21am UTC](https://boards.straightdope.com/t/is-it-really-this-easy-to-circumvent-a-macbook-passord/964724/5 "2022-05-20T05:21:20Z")

</div>

No, I did not. I guess that was the step that I was missing.

---

<div class="post-metadata">

**Author:** ![Francis\_Vaughan](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/francis_vaughan/32/3093_2.png) [@Francis\_Vaughan](https://boards.straightdope.com/u/Francis_Vaughan)\
**Post date:** [May 20, 2022, 6:26am UTC](https://boards.straightdope.com/t/is-it-really-this-easy-to-circumvent-a-macbook-passord/964724/6 "2022-05-20T06:26:59Z")

</div>

In general, if you have physical access to a machine and nothing is encrypted, you can break security. File vault and keychain encrypt their contents. No password to these and you are not getting far. Otherwise it is just speed bumps on the way in, and no roadblocks.

MacOS follows the more modern tactic of disabling root login and enabling sudo aka administrator access on selected accounts to allow for system management tasks. Those of us from a bygone era still miss root access as a way of working. (One can still put a password on the root account if wanted.)

But once one has physical access, the machine is yours. Encryption protects the data only.

In the modern world it is best to regard the physical computer as a cache for your data and as a device to perform computation. Have a local encryption protected copy of your digital life on the computer, but the master copy in a secure system that is not subject to theft, disaster or malfeasance. It should be possible to lose the computer and be able to restore your world onto a brand new computer with only minor upset. Apple do an OK, but imperfect implementation of this.
