So far we are talking about our own low level (possibly assembly) construction of BIOS instructions (for step 1)
to do that, you will need a large program. So we dont have a "bios" but an entire O/S on ROM.

although its look more secure, its just a matter to attack the bios, not the o.s. nowadays ppl attacks "software O.S" because its easier. But if you hardlock thru bios, they will instead attack the hardlock - bios program.

my idea :

an external device (USB/card) where you insert your id. when you have inserted your id card (or usb device), system(bios perhaps) will ask the password, that servers to open "the card". if the card "accepts" you, card you send a 4096 key to bios to decript hard disk and start boot (you have encript the HD before with your card).

so, no password stored on disk - you can carry your password with you. Maybe the card can have a fingerprint reader, so it can "see" if you are the owner of the card or not.


ahn, you got me. that device already exists ! (not with bios but as a low level encrypt software)