Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Multifunction Printers: The Forgotten Security Risk?
Slashdot ^ | 2-13-08 | ScuttleMonkey

Posted on 02/14/2008 7:36:11 AM PST by STARWISE

REFERENCES ARTICLE FROM SOURCE THAT CAN'T BE POSTED HERE.

~~~~~

eweekhickins writes to share an article *snip* highlighting the forgotten risks that a multifunction printer could possibly offer. Brendan O'Connor first called attention to the vulnerabilities of these new devices at a Black Hat talk in '06 and warns that these are no longer "dumb" machine sitting in the corner and should be treated with their own respective security strategy.

~~~~

Forum post on Slashdot:

~~~~

"The biggest issue isn't a lack of (software or physical) security regarding the machine, but a lack of a security policy in these instances.

At our institution, machines have unique names, unique passwords (when they have to scan to a network drive), and are behind the campus firewall. But a user could get one, hook it up (putting it behind the firewall) and not change the default password and we'd 1) be none the wiser and 2) have no control over the machine. If a department gets one, it's their printer, not ours.

Still, with client-side antivirus and firewalls, and the control we have over the servers (for a multifunction printer to be able to scan to a server, it has to be given specific access, which doesn't happen lightly), it doesn't seem like being able to access the web interface can pose a whole lot of a threat.

An attacker could potentially waste a ream of paper or two, a bit of toner, but I don't foresee any major consequences."

(Excerpt) Read more at it.slashdot.org ...


TOPICS: Business/Economy; Miscellaneous; Society
KEYWORDS: multifunction; printers; security; worms
Color me stunned. If this applies to all multifunction printers and not only to networked multifunction printers, how do you get an anti-virus program for a single multifunction printer?
1 posted on 02/14/2008 7:36:15 AM PST by STARWISE
[ Post Reply | Private Reply | View Replies]

To: STARWISE
...how do you get an anti-virus program for a single multifunction printer?

I don't think there are any.

2 posted on 02/14/2008 7:45:06 AM PST by rabscuttle385 (Admin Moderator for President. No amnesty for the establishment—Republican and Democrat!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ThePythonicCow; MNJohnnie; Phsstpok

~PING!


3 posted on 02/14/2008 7:52:28 AM PST by STARWISE (They (Dims) think of this WOT as Bush's war, not America's war-RichardMiniter, respected OBL author)
[ Post Reply | Private Reply | To 2 | View Replies]

To: STARWISE

Many multi-function printers also come with slots for various types of camera media. Thus effectively making them network-atttached disk drives.


4 posted on 02/14/2008 8:22:32 AM PST by Noumenon (The only thing that prevents liberals from loading us all into cattle cars is the power to do it)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Noumenon
Even without a media slot, most of them are network attached storage ... in that they have disk storage built in.
5 posted on 02/14/2008 8:49:41 AM PST by ThePythonicCow (The Greens and Reds steal in fear of freedom and capitalism; Fear arising from a lack of Faith.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: ThePythonicCow

Is there any way to protect a single
multifunction printer, TPC ? I knew
you’d have some advice ... thanks in
advance ... ;)


6 posted on 02/14/2008 8:55:59 AM PST by STARWISE (They (Dims) think of this WOT as Bush's war, not America's war-RichardMiniter, respected OBL author)
[ Post Reply | Private Reply | To 5 | View Replies]

To: STARWISE
You don't. Not now anyway. Which is ok, as you don't need one, yet anyway.

If I were managing printers inside the Pentagon, or inside a major defense contractor, I'd be thinking really carefully about this one. And if I were managing IT inside a big company, I'd be doing as the article suggests, starting to talk up my printer vendors on this, to see what story they have, to begin to encourage them to actually get a clue, and to begin to reward those who take this seriously with more business.

But I see no evidence that this is the year that those of us in small, mundane businesses, or those of us at home or in home offices, should worry. I'll be spending about as much time worrying about this as I worry about threat vectors for Lockheed C-5A Galaxy transports.

Besides, even if it was the year for us ordinary folks to worry about this, there ain't a damn thing you can do yet, except that which would be more effort than it was worth, and require specialized expertise that few have.

Printers are certainly potential threat vectors. They are special purpose computers sitting on the network, ill managed and fully equipped. But (1) the potential isn't being realized yet -- crackers haven't mounted widespread attacks using them yet, and (2) nor are the practical protections there yet either -- neither printer nor security vendors have much to sell you here, nor do us Open Software hackers have much for you to download, compile and mess with yourself, that any ordinary person would find useful.

7 posted on 02/14/2008 9:18:20 AM PST by ThePythonicCow (The Greens and Reds steal in fear of freedom and capitalism; Fear arising from a lack of Faith.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: STARWISE
No practical way, no real need, not this year, and probably not next year either.

If you're a Gold Star member of the tin foil hat society, or if you choose (for reasons of modest income or of Green persuasions) to pinch pennies, I suppose you could leave your printer powered off when you aren't using it.

You could put a router, custom configured, in front of your printer to keep out all but print traffic. That's actually doable, and would block much of the potential risk. Your time would be better spent taking a walk and enjoying the sunset.

8 posted on 02/14/2008 9:29:13 AM PST by ThePythonicCow (The Greens and Reds steal in fear of freedom and capitalism; Fear arising from a lack of Faith.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: ThePythonicCow

Thank you for your insights and advice. ..I guess
I’ll just be Scarlett and worry about that tomorrow .. ;)


9 posted on 02/14/2008 11:18:30 AM PST by STARWISE (They (Dims) think of this WOT as Bush's war, not America's war-RichardMiniter, respected OBL author)
[ Post Reply | Private Reply | To 8 | View Replies]

To: STARWISE
Yeah ... if you're looking for something to worry about, there's plenty of more pressing matters to choose from ;).
10 posted on 02/14/2008 11:37:33 AM PST by ThePythonicCow (The Greens and Reds steal in fear of freedom and capitalism; Fear arising from a lack of Faith.)
[ Post Reply | Private Reply | To 9 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson