I am just booting my new X1 for the first time, and went into the bios to set a bios password. I discovered a slew of security settings:
- Supervisor password
- Lock UEFI BIOS Settings (enabled/disabled)
- Password at Unattended Boot (enabled/disabled)
- Password at Restart (enabled/disabled)
- Password at Boot Device List (enabled/disabled)
- Password Count Exceeded Erro (enabled/disabled)
- Set Minimum Length (integer)
- Power-On Password
- Hard Disk1 Password (text field, need to choose "User" or "User+Master")
So - I have the option of typing 3 distinct bios passwords (not including the OS password), and enabling or disabling it at various points in the boot cycle.
What's a good, secure setup to use that's still convenient? Why do I need 3 distinct BIOS passwords? Which of the checkpoints should be put on enabled ?
Also - I intend to enable full disk encryption using Bitlocker. Does it make some of these options reduntant?