source: http://www.securityfocus.com/bid/3186/info

A user who has set an Open Firmware password on their Apple system believes it to be safe when powered down. There is a tool that any user with access to the Finder can run in order to reveal the Open Firmware password without any decryption.

http://www.exploit-db.com/sploits/21070.sit