HP CEO evokes James Bond-style hack via ink cartridges
arstechnica.com
external-link
"Our long-term objective is to make printing a subscription."

His claims are quickly debunked in the article, as the true reason is, obviously, protecting their IP and subscription model

@floofloof@lemmy.ca
link
fedilink
English
22
edit-2
9M

Shivaun Albright, HP’s chief technologist of print security, said at the time:

“A researcher found a vulnerability over the serial interface between the cartridge and the printer. Essentially, they found a buffer overflow. That’s where you have got an interface that you may not have tested or validated well enough, and the hacker was able to overflow into memory beyond the bounds of that particular buffer. And that gives them the ability to inject code into the device.”

Albright added that the malware “remained on the printer in memory” after the cartridge was removed.

So HP had a vulnerability in their printer’s firmware that allowed arbitrary cartridge code to become executable, and they’re trying to spin this so it doesn’t sound like their printers are at fault. Still sounds like a them problem.

Create a post

A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.

Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.

Subcommunities on Beehaw:


This community’s icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

  • 1 user online
  • 61 users / day
  • 171 users / week
  • 620 users / month
  • 2.31K users / 6 months
  • 1 subscriber
  • 3.28K Posts
  • 67K Comments
  • Modlog