You are correct, you can reset the open firmware that way. If you are worried about security then remember that once someone can touch your computer they will be able to do what they want to it. You can encrypt your drive but if you have a crash kiss your data goodbye as a recovery utility won't be able to recover it.
If you want to stop the casual abuser then format your partition to ufs and if you must use classic have it on a different drive or a separate partition. OS9 discs will not be able to see the ufs area. when you boot from the installer cd you can reset the root password from the cd.