Note that the firmware password can be bypassed by any Apple tech who calls into their call center, identifies themselves, and requests it. It's defense against a casual thief, but not someone with Apple connections, LEA, or any of thousands of Apple employees and third-party repair places. Still worth doing, just not as secure as the ones on old IBM thinkpads, say.