hp

How Printers Help Hackers Hide In Plain Sight

Printers and Hackers

Spies and thieves often do their best work by hiding in plain sight. No one suspects the person sipping coffee at the table across from you in the coffee shop – the one who happens to be reading your computer through the unsecured Wi-Fi. No one ever thinks that the PIN they enter at the ATM or debit card terminal is being watched by someone a few feet away. Few people consider the danger of including their real birthdate when opening a membership online. And certainly no one ever suspects the printer of anything at all except occasionally needing paper.

But these are all examples of how we use technology daily to solve our immediate concerns without additional thought. Life would be very hard without Wi-Fi, ATMs and printers. Their roles are as quiet, subservient support technologies. They are the discreet butlers of our digital lives. No one ever suspects the butler.

It is for that reason – that lack of diligence – that printers have become the gaping hole in the wall of cybersecurity. Companies spend billions of dollars annually seeking to protect networks and ensure that computers are safe and virus free. But few people pay attention to the silent peripherals.

Decision makers seldom hear about hacks through printers. To the average, honest working person, they are simply output devices. But to the wearers of the black hats, they are willing and compliant access points, not only to a company's existence, but beyond, to everything that company is connected to, out there on the internet.

The most infamous DDoS attack in recent memory happened on October 21, 2016, when a brand of malware called Mirai brought Netflix, Twitter, Amazon and others to a crawl. Experts believe this malware made its entrance through an unprotected Internet of Things (IoT) device like a printer, a router or a camera. These are devices that are seldom protected by vigorous passcodes and anti-hacking tools. They're just simple devices after all.

But this is where innocence and naiveté have no place. The belief that such devices are low risk, having little value to hackers, is fatally incorrect. To remain unaware of just how a sophisticated hacker can use an unsecured printer to access the network is precisely the type of thinking that can bring companies down. To forget just what lives inside a printer – images of documents, user credentials – is downright dangerous.

Get Everything and Everyone into the Audit

Every device, no matter how innocent looking, must be included inside a rigorous and regular security audit, must be monitored regularly, and must be brought up to speed in terms of security software. If a device can communicate, if it has a computer inside, no matter how small, it can be compromised.

The people who use these devices must be trained in the same type of hygiene that they currently (hopefully) apply to their network passwords and laptops. There must be a mechanism to enforce policies.

It's Not Just External Spies

Printer security does not end with shoring up the software. Companies must also consider the people on the inside who are using these devices daily.

  • How are they sending? Wirelessly? Is this allowed? Is it being done securely?
  • Are they sending to a remote printer in an office miles away? If so, who might be there? What might they see?
  • Are they operating within normal behavior patterns? For example, when a person who generally makes five copies a day, makes a few hundred copies on a quiet Sunday morning, this is an unusual behavior pattern worthy of investigation.
  • Do your printers have whitelists or credential tables allow specific access and activity privileges to each employee?
  • Are passwords being used correctly and changed regularly? Are employees complying?
  • Are employees actually communicating with the printer they think they are?

The key message is that printers play a fundamental role in business life, both at the workplace and in peoples' homes. They are communications devices armed with computing power, and if left unsecured, they become dangerous. Secure printers must be equipped with features like secure whitelisting, run-time intrusion detection, automated compliance, usage certificates, and even a “golden BIOS copy” to revert to, should a compromise be detected.

As more and more devices connect to the global network, they increase convenience, but at a cost of substantially weakened security. A printer that is not secure should be turned off and physically disconnected, since the bad guys are getting much better at hiding in plain sight.

For more information on printer security, visit HP's Secure printing page and check out the webinar. To do a quick self analysis of your printers, visit HP's analysis page here.

This post is brought to you by HP and IDG.

The views and opinions expressed herein are those of the author(s) and do not necessarily represent the views and opinions of HP.

By Steve Prentice

Steve Prentice

Steve Prentice is a project manager, writer, speaker and expert on productivity in the workplace, specifically the juncture where people and technology intersect. He is a senior writer for CloudTweaks.

View Website

CONTRIBUTORS

Safeguarding Data Before Disaster Strikes

Safeguarding Data Before Disaster Strikes

Safeguarding Data  Online data backup is one of the best methods for businesses of all sizes to replicate their data ...
Cloud Services Are Vulnerable Without End-To-End Encryption

Cloud Services Are Vulnerable Without End-To-End Encryption

End-To-End Encryption The growth of cloud services has been one of the most disruptive phenomena of the Internet era.  However, ...
AWS S3 Outage & Lessons in Tech Responsibility From Smokey the Bear

AWS S3 Outage & Lessons in Tech Responsibility From Smokey the Bear

AWS S3 Outage & Lessons in Tech Responsibility Earlier this week, AWS S3 had to fight its way back to ...
Cyber Security Tips For Digital Collaboration

Cyber Security Tips For Digital Collaboration

Cyber Security Tips October is National Cyber Security Awareness Month – a joint effort by the Department of Homeland Security ...
Why ‘Data Hoarding’ Increases Cybersecurity Risk

Why ‘Data Hoarding’ Increases Cybersecurity Risk

Data Hoarding The proliferation of data and constant growth of content saved on premise, in cloud storage, or a non-integrated ...
Battle of the Clouds: Multi-Instance vs. Multi-Tenant Architecture

Battle of the Clouds: Multi-Instance vs. Multi-Tenant Architecture

Multi-Instance vs. Multi-Tenant Architecture  The cloud is part of everything we do. It’s always there backing up our data, pictures, ...
3 Ways to Protect Users From Ransomware With the Cloud

3 Ways to Protect Users From Ransomware With the Cloud

Protect Users From Ransomware The threat of ransomware came into sharp focus over the course of 2016. Cybersecurity trackers have ...
Imminent IoT Eye-Tracking Technologies To Transform The Connected World

Imminent IoT Eye-Tracking Technologies To Transform The Connected World

IoT Eye Tracking Smelling may be the first of the perceptible senses, but the eye is the fastest moving organ ...
The Rise Of BI Data And How To Use It Effectively

The Rise Of BI Data And How To Use It Effectively

The Rise of BI Data Every few years, a new concept or technological development is introduced that drastically improves the ...
Countdown to GDPR: Preparing for Global Data Privacy Reform

Countdown to GDPR: Preparing for Global Data Privacy Reform

Preparing for Global Data Privacy Reform Multinational businesses who aren’t up to speed on the regulatory requirements of the European ...

NEWS

email as a service

Google Data Analysis, Artificial Intelligence and Predicting Vaccine Scares

Social media trends can predict tipping points in vaccine scares Analyzing trends on Twitter and Google can help predict vaccine ...
Deloitte TMT Predictions: Machine Learning Deployments, On-Demand Content and Live Events Will Continue to Drive Growth

Deloitte TMT Predictions: Machine Learning Deployments, On-Demand Content and Live Events Will Continue to Drive Growth

NEW YORK, Dec. 12, 2017 /PRNewswire/ -- Deloitte forecasts double digital growth in machine learning deployments for the enterprise, an increasing worldwide ...
U.S. IT Sector Employment Expands by 8,100 Jobs in November, CompTIA Analysis Reveals

U.S. IT Sector Employment Expands by 8,100 Jobs in November, CompTIA Analysis Reveals

DOWNERS GROVE, Ill., Dec. 8, 2017 /PRNewswire-USNewswire/ -- New hiring in computer and electronics manufacturing and technology services and custom ...