HP says its printers won't catch fire even if maliciously attacked by hackers-- not its current lineup at least. We're seeking clarification about whether all legacy models come with a thermal breaker.
Company admits vulnerability exists, but claims it only affects Macs and Linux machines

Hewlett Packard Comp. (HPQ) fired back after MSNBC covered recent research on a "devastating" printer driven attack.  Conducted by Columbia University, the resarch showed HP printers being forced to overheat after being exploited via a malicious firmware update.  The HP printer in the test attack did overheat but did not catch on fire as the thermal breaker shut down when in sensed the internal temperature rise.  Thus the paper was browned, indicating high temperature near-combustion reactions, but no full combustion and no blaze.

HP was upset, apparently at the Columbia University researchers' claim that some HP printers might lack the thermal breaker and completely catch on fire.  They were also upset about the allegation that Windows users might be vulnerable to the exploit.  The attack was done on a Linux machine, and HP states that it believes that only Macs and Linux machines are vulnerable to the attack.

HP writes to us in a tersely worded email:

Today there has been sensational and inaccurate reporting regarding a potential security vulnerability with some HP LaserJet printers. No customer has reported unauthorized access. Speculation regarding potential for devices to catch fire due to a firmware change is false. 

HP LaserJet printers have a hardware element called a "thermal breaker" that is designed to prevent the fuser from overheating or causing a fire. It cannot be overcome by a firmware change or this proposed vulnerability.

While HP has identified a potential security vulnerability with some HP LaserJet printers, no customer has reported unauthorized access. The specific vulnerability exists for some HP LaserJet devices if placed on a public internet without a firewall. In a private network, some printers may be vulnerable if a malicious effort is made to modify the firmware of the device by a trusted party on the network. In some Linux or Mac environments, it may be possible for a specially formatted corrupt print job to trigger a firmware upgrade.

HP is building a firmware upgrade to mitigate this issue and will be communicating this proactively to customers and partners who may be impacted. In the meantime, HP reiterates its recommendation to follow best practices for securing devices by placing printers behind a firewall and, where possible, disabling remote firmware upload on exposed printers.

HP will continue to educate customers about security risks and the features available to address them, and take proactive steps to maintain the security of devices in the field. HP Imaging and Printing Security Solutions work directly at the device and on the network to protect information at rest and in motion, and to prevent unauthorized access. 

In other words, HP admits that its printers could, in theory, be taken over by hackers, but it doesn't believe that to have happened yet and it doesn't believe its printers are capable of catching on fire sort of takeover scenario.

While most of its commentary does sound about right, there's a couple of outstanding issues here.  First, HP suggests that "HP LaserJet printers have a hardware element called a 'thermal breaker'."

The issue here is the word "have", as in the present tense.  It is unclear when this became standard across HP's lineup.  We're reaching out to HP to find out.

Edit (6:09 p.m.) : 
A 1996 book on printer repair indicates that series thermiresistors (aka the "thermal breaker") are standardly used in series with the fuser elements in printers.  It's unclear what Columbia University/MSNBC meant by claiming that some models could be vulnerable to fire.  It is possible that they were unaware of this design paradigm and still haven't figured it out.

The second issue is HP's portrayal of this as an attack that's only possible if the printer is a Linux/Mac machine "placed on a public internet" or the attempt is made by "a trusted party on the network".  While this is technically accurate, it fails to mention that all it would take to carry out the assault on a local corporate network would be one hijacked Mac/Linux box with print permissions.  The jacked box would be able to scan for local printers or looked at saved settings and ID target HP printers.  

Depending on how tight the IT monitoring was, the attacker could even install a Linux partition or virtual machine on a Windows box to complete the attack, assuming no compromised Linux/Mac machines were available.  Likewise with a Windows-connected internet printer, even if Windows itself was not vulnerable, an attacker could gain access to the system in other ways and then install a Linux partition and boot to it, accessing the printer in that manner.

Of course these attacks would require a fair level of sophistication, so it's hardly the kind of thing your average SQL injection "script kiddies" could pull off.  At this point such attacks seem unlikely to happen, unlikely more so to happen very often.  But there have been surprisingly sophisticated in-the-wild exploits in the past both from private sector black hats and by nation state players, and when you add in the potential for terrorism, it's not entirely unfeasible that an attack on an unpatched machine could occur, given HP's market prevalence as the world's biggest manufacturer of printers.

HP -- whether it likes it or not -- better react quickly with all its available partners to patch the issue on all legacy printers.  Because god forbid if terrorists or cybercriminals did steal someone's identity or set their printer on fire via malformed firmware updates, HP would see worlds more negative PR than it's seeing now.

Thus while getting the right story out there is important -- and still a work in progress for MSNBC, HP, and Columbia University, all of whom are probing the full extent of this set of vulnerabilities -- it's equally important that story is out there.  Because given the media scrutiny, the issue now becomes one HP is forced to fix immediately.

Secunia back in August reported that numerous HP Photosmart printers were subject to potential remote attacks by malicious users'.  In its security advisory Secunia writes:

Some vulnerabilities have been reported in multiple HP Photosmart printers, which can be exploited by malicious people to conduct cross-site scripting attacks, disclose potentially sensitive information, and manipulate certain data.

1) Certain unspecified input is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

2) An unspecified error in the webscan component can be exploited to disclose certain information.

3) An unspecified error in the SNMP component can be exploited to disclose or manipulate certain data.

HP confirmed this vulnerability for numerous models and has released a preventive firmware patch.

Firmware-level attacks have seen growing interest both in the black hat and cybersecurity ("white hat") communities, although attacks in the wild using such sophisticated exploits remain almost nonexistent.

Source: (email)

"I'd be pissed too, but you didn't have to go all Minority Report on his ass!" -- Jon Stewart on police raiding Gizmodo editor Jason Chen's home

Latest Headlines
MSI GL62M 7REX Gaming Laptop
August 14, 2017, 6:00 AM
SoundCloud survives the budge scare
August 12, 2017, 6:38 AM
Dell XPS 27
August 9, 2017, 6:00 AM
ASRock B250 Pro4
August 7, 2017, 6:00 AM
Top 3 Motherboards
August 4, 2017, 6:00 AM
Titan Xp vs GTX 1080 Ti
August 3, 2017, 6:13 AM

Most Popular ArticlesSony’s 4K OLED Smart TV
August 13, 2017, 6:20 AM
Ticwatch E and S on Kickstarter
August 11, 2017, 6:00 AM
SoundCloud survives the budge scare
August 12, 2017, 6:38 AM
Acer Chromebook 11 C771 – Durable Education Companion
August 10, 2017, 6:40 AM
Mobile C50 Flash Drive
July 30, 2017, 6:00 AM

Latest Blog Posts
Xiaomi Mi 6 Smartphone.
Nenfort Golit - Aug 8, 2017, 6:00 AM
ASUS 23-inch Monitor
Nenfort Golit - Aug 4, 2017, 6:00 AM

Copyright 2017 DailyTech LLC. - RSS Feed | Advertise | About Us | Ethics | FAQ | Terms, Conditions & Privacy Information | Kristopher Kubicki