HP CEO: Blocking third-party ink from printers fights viruses

BlackEco@lemmy.blackeco.com to Technology@beehaw.org – 160 points –
HP CEO evokes James Bond-style hack via ink cartridges
arstechnica.com

His claims are quickly debunked in the article, as the true reason is, obviously, protecting their IP and subscription model

41

You are viewing a single comment

I personally love how they gave ink cartridges the ability to execute arbitrary code. Not like there are ways for them to have a signed hash or something that could do the same amount of validation, but actual code. That's HP's fuckup, not ours.

It wasn't quite that; there was a buffer overflow in the code that was talking to the ink cartridge. So a malicious ink cartridge could in fact take over your printer. Of course, a web page you visit could in fact take over your browser and that's a much more realistic threat vector, and somehow we've survived all this time without limiting ourselves to HP-sponsored and security-assured web pages with a healthy cut of profit going to HP from every visit.

in the code that was talking to the ink cartridge.

So the flaw is in the printer or driver, and HP has just admitted to shipping an insecure, nay negligently dangerous, product to consumers?

In the 90s, they shipped recovery CDs with viruses baked in. Knowingly shipping destructive code and hardware is kinda HP's thing.

I've not heard about this. Does anyone have a link to share? Can't find one myself

This was 95ish. We were under strict orders not to confirm it. HP worked hard to keep it under wraps. Now layer on the fact the web was still in its infancy, you likely won't find a whole lot about it.

1 more...

well that makes a bit more sense, thanks for clearing it up. Still stupid, but not as bad as I had been lead to believe.

1 more...
1 more...