163

His claims are quickly debunked in the article, as the true reason is, obviously, protecting their IP and subscription model

top 42 comments
sorted by: hot top controversial new old
[-] megopie@beehaw.org 121 points 9 months ago* (last edited 9 months ago)

“ See ink cartridges can be vectors for viruses because they have chips in them.”

“Why does a container of ink have chips in it?”

“To make sure you don’t use third party ink cartridges”

[-] mp3@lemmy.ca 58 points 9 months ago

HP is the virus.

[-] Talaraine@kbin.social 15 points 9 months ago

Case closed.

[-] BreakDecks@lemmy.ml 2 points 9 months ago

The virus thing is bullshit, but inkjet cartridges usually have chips in them because the print head requires a digital controller. They aren't generally just a container of ink.

Now, using the need for a controller to add anti-consumer lockouts? That's what we call malware.

[-] megopie@beehaw.org 1 points 9 months ago

Didn’t they remove the chips from inkjet cartridges during the chip shortage during the pandemic?

[-] Doxin@yiffit.net 1 points 9 months ago

By far most ink cartridges come without heads. The heads are mounted in the printer itself. Even if the head is on the cartridge the controller can still be in the printer.

[-] AnonTwo@kbin.social 44 points 9 months ago

So basically they're protecting you from something that's only possible, because of something they shouldn't have done.

[-] mozz@mbin.grits.dev 35 points 9 months ago* (last edited 9 months ago)

Unsurprisingly, Lores' claim comes from HP-backed research. The company's bug bounty program tasked researchers from Bugcrowd with determining if it's possible to use an ink cartridge as a cyberthreat. HP argued that ink cartridge microcontroller chips, which are used to communicate with the printer, could be an entryway for attacks.

As detailed in a 2022 article from research firm Actionable Intelligence, a researcher in the program found a way to hack a printer via a third-party ink cartridge. The researcher was reportedly unable to perform the same hack with an HP cartridge.

Shivaun Albright, HP's chief technologist of print security, said at the time:

"A researcher found a vulnerability over the serial interface between the cartridge and the printer. Essentially, they found a buffer overflow. That’s where you have got an interface that you may not have tested or validated well enough, and the hacker was able to overflow into memory beyond the bounds of that particular buffer. And that gives them the ability to inject code into the device."

This is a remarkable amount of effort and money to spend trying to demonstrate the "truth" of something which everyone involved was surely aware was bullshit from start to finish. I'm honestly at a loss to figure out what was the point, unless the point was "help me help I have too much money what am I gonna do with all this money."

(I looked it up, and the bug bounty program awarded "up to" $10,000. So maybe they just made the guy sign an NDA then gave him $100 and said thanks for helping us with our lying sucker, now get lost.)

[-] scrubbles@poptalk.scrubbles.tech 33 points 9 months ago

I personally love how they gave ink cartridges the ability to execute arbitrary code. Not like there are ways for them to have a signed hash or something that could do the same amount of validation, but actual code. That's HP's fuckup, not ours.

[-] mozz@mbin.grits.dev 16 points 9 months ago

It wasn't quite that; there was a buffer overflow in the code that was talking to the ink cartridge. So a malicious ink cartridge could in fact take over your printer. Of course, a web page you visit could in fact take over your browser and that's a much more realistic threat vector, and somehow we've survived all this time without limiting ourselves to HP-sponsored and security-assured web pages with a healthy cut of profit going to HP from every visit.

[-] Overzeetop@beehaw.org 15 points 9 months ago

in the code that was talking to the ink cartridge.

So the flaw is in the printer or driver, and HP has just admitted to shipping an insecure, nay negligently dangerous, product to consumers?

[-] Banzai51@midwest.social 5 points 9 months ago

In the 90s, they shipped recovery CDs with viruses baked in. Knowingly shipping destructive code and hardware is kinda HP's thing.

[-] anytimesoon@lemmy.ml 2 points 9 months ago

I've not heard about this. Does anyone have a link to share? Can't find one myself

[-] Banzai51@midwest.social 1 points 9 months ago

This was 95ish. We were under strict orders not to confirm it. HP worked hard to keep it under wraps. Now layer on the fact the web was still in its infancy, you likely won't find a whole lot about it.

[-] Bitrot@lemmy.sdf.org 4 points 9 months ago

They all have flaws, that's ostensibly why they also provide firmware updates. I think it's likely their software team even fixed the original flaw while their make more money team extended it into locking down products even more.

[-] scrubbles@poptalk.scrubbles.tech 3 points 9 months ago

well that makes a bit more sense, thanks for clearing it up. Still stupid, but not as bad as I had been lead to believe.

[-] SnotFlickerman@lemmy.blahaj.zone 11 points 9 months ago* (last edited 9 months ago)

This is a remarkable amount of effort and money to spend trying to demonstrate the “truth” of something which everyone involved was surely aware was bullshit from start to finish.

See the Return to Office mandates and basically anything and everything corporate-mandated. CEOs have shown they don't actually give a flying fuck what research tells them, they'll go with their "gut instinct" every time when their gut instinct always boils down to "Fuck you, I've got mine, nevermind that I got it by stealing it from you."

They'll spend millions chasing thousands, they always do. The rich are only successful because of the wealth they can endlessly fall back on, the rest of us are completely fucked when we make the endless mistakes they make. It's part of why they think they're infallible, since their wealth insulates them from real consequences.

[-] falsem@kbin.social 6 points 9 months ago

That sounds an awful lot like even their first party cartridges could be attack vectors.

[-] mozz@mbin.grits.dev 8 points 9 months ago

Yes. I suspect that when they say the printers are only vulnerable via third-party cartridges, they mean that obviously no genuine HP cartridge would contain malicious software, therefore any malicious cartridge is by definition third party, therefore the printers are only vulnerable via third-party cartridges.

[-] MonkderZweite@feddit.ch 1 points 9 months ago

Well, at least he can explain technical stuff somewhat coherently.

[-] reverendsteveii@lemm.ee 24 points 9 months ago

every once in a while they'll just tell you how stupid they think you are. don't ever forget it.

[-] SnotFlickerman@lemmy.blahaj.zone 23 points 9 months ago

This has real "Home Taping is Killing Music" vibes.


But god damn do these corporate vultures really think that we owe them something.

No, this is a financial transaction. I am buying a product from you, and once I have paid you, I owe you nothing more. Endless attempts to make your business model endlessly extractive from your customer base just shows you have shitty business management skills and don't know how to grow your business outside of nickel-and-diming people to death.

[-] floofloof@lemmy.ca 22 points 9 months ago* (last edited 9 months ago)

Shivaun Albright, HP's chief technologist of print security, said at the time:

"A researcher found a vulnerability over the serial interface between the cartridge and the printer. Essentially, they found a buffer overflow. That’s where you have got an interface that you may not have tested or validated well enough, and the hacker was able to overflow into memory beyond the bounds of that particular buffer. And that gives them the ability to inject code into the device."

Albright added that the malware “remained on the printer in memory” after the cartridge was removed.

So HP had a vulnerability in their printer's firmware that allowed arbitrary cartridge code to become executable, and they're trying to spin this so it doesn't sound like their printers are at fault. Still sounds like a them problem.

[-] waspentalive@beehaw.org 13 points 9 months ago* (last edited 9 months ago)

The mad rush to sell the sizzle, not the steak.

Wouldn't it be nice to have one company create a simple printer that just prints. It does not have a local webpage. It does not monitor your ink supplies. It does not phone home. It uses ink from bottles sold inexpensivly.

[-] Midnitte@beehaw.org 4 points 9 months ago

Would be less hassle to just fucking 3d print a page

[-] progandy@feddit.de 3 points 9 months ago

The last point does exist, those printers are just more expensive because they are no loss leaders and no ink sales are expected.

[-] DeltaTangoLima@reddrefuge.com 12 points 9 months ago

Lol - this week in "When Clueless Leaders Try and Talk Tech"

[-] furrowsofar@beehaw.org 11 points 9 months ago* (last edited 9 months ago)

I guess it is HP think it is OK to brick your printer due to HP updates but using competing cartridges is just so dangerous. Typical.

I never heard what happened to those bricked printers.

[-] Thisfox@sopuli.xyz 2 points 9 months ago

Well, I doubt they plan to ever buy HP again.

[-] neuracnu@lemmy.blahaj.zone 10 points 9 months ago

The CEO of HP, Enrique Lores, has explicitly said that the company is aiming to turn printing into a service model.

Our long-term objective is to make printing a subscription," Lores said. "This is really what we have been driving."

Fuck this noise.

https://news.yahoo.com/hp-ceo-says-goal-printing-223058918.html

[-] thefartographer@lemm.ee 8 points 9 months ago

The only obvious solution to this new threat is to add certificates to their cartridge chips. And if you don't use up your signed cartridges within the year that the cartridges had valid certificates, that's really on you. Also, since we're so worried about security on our ink cartridges, I'd like to be charged an extra $5 per cartridge if I'd like to register them with McAfee. /s

Also, maybe HP should consider that putting words and images on dead trees is only being accelerated towards its grave by their greedy practices.

[-] reverendsteveii@lemm.ee 6 points 9 months ago

surely for some small fee I can refresh the cartridge chip certificate

[-] thefartographer@lemm.ee 7 points 9 months ago

That feature will only be enabled after extensive "research" following the "Crushed Grandma Landfill Disaster of 2135." A tragedy in which the massive landfill of unused ink cartridges shifts and engulfs an entire city block, crushing one grandmother to death.

[-] reverendsteveii@lemm.ee 7 points 9 months ago

We paid researchers to determine if Grandmas can be crushed by mountains of third-party ink cartridges

[-] thefartographer@lemm.ee 6 points 9 months ago* (last edited 9 months ago)

I just tried so hard to stifle my laughter at work that I instead ended up wheeze-giggling and then loudly farting. Holy shit this comment makes me laugh way too hard, I almost want to print it out.

[-] milkytoast@kbin.social 4 points 9 months ago

IM EATING SOUP, ARE YOU TRYING TO KILL ME????

[-] mustbe3to20signs@feddit.de 4 points 9 months ago

Sustainability of a business strategy? But wouldn't that cost them those sweet short term gains?

[-] RandomVideos@programming.dev 2 points 9 months ago

Using HP ink reduces the chances of getting sick by 0.001%

[-] DonQuixote@beehaw.org 1 points 9 months ago

I still have a black spot on my lung from a rogue ink cartridge. That's why HP wants to put theirs on prescription.

[-] sarmale@lemmy.zip 1 points 9 months ago

Then dont make them with chips 🤦‍♂️

[-] autotldr@lemmings.world 1 points 9 months ago

🤖 I'm a bot that provides automatic summaries for articles:

Click here to see the summaryLast Thursday, HP CEO Enrique Lores addressed the company's controversial practice of bricking printers when users load them with third-party ink.

That frightening scenario could help explain why HP, which was hit this month with another lawsuit over its Dynamic Security system, insists on deploying it to printers.

HP has issued firmware updates that block printers with such ink cartridges from printing, leading to the above lawsuit (PDF), which is seeking class-action certification.

Still, because chips used in third-party ink cartridges are reprogrammable (their “code can be modified via a resetting tool right in the field,” according to Actionable Intelligence), they’re less secure, the company says.

Further, there's a sense from cybersecurity professionals that Ars spoke with that even if such a threat exists, it would take a high level of resources and skills, which are usually reserved for targeting high-profile victims.

Realistically, the vast majority of individual consumers and businesses shouldn't have serious concerns about ink cartridges being used to hack their machines.


Saved 79% of original text.

this post was submitted on 22 Jan 2024
163 points (100.0% liked)

Technology

37573 readers
206 users here now

A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.

Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.

Subcommunities on Beehaw:


This community's icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

founded 2 years ago
MODERATORS