His claims are quickly debunked in the article, as the true reason is, obviously, protecting their IP and subscription model

  • mozz@mbin.grits.dev
    link
    fedilink
    arrow-up
    29
    ·
    edit-2
    10 months ago

    Unsurprisingly, Lores’ claim comes from HP-backed research. The company’s bug bounty program tasked researchers from Bugcrowd with determining if it’s possible to use an ink cartridge as a cyberthreat. HP argued that ink cartridge microcontroller chips, which are used to communicate with the printer, could be an entryway for attacks.

    As detailed in a 2022 article from research firm Actionable Intelligence, a researcher in the program found a way to hack a printer via a third-party ink cartridge. The researcher was reportedly unable to perform the same hack with an HP cartridge.

    Shivaun Albright, HP’s chief technologist of print security, said at the time:

    “A researcher found a vulnerability over the serial interface between the cartridge and the printer. Essentially, they found a buffer overflow. That’s where you have got an interface that you may not have tested or validated well enough, and the hacker was able to overflow into memory beyond the bounds of that particular buffer. And that gives them the ability to inject code into the device.”

    This is a remarkable amount of effort and money to spend trying to demonstrate the “truth” of something which everyone involved was surely aware was bullshit from start to finish. I’m honestly at a loss to figure out what was the point, unless the point was “help me help I have too much money what am I gonna do with all this money.”

    (I looked it up, and the bug bounty program awarded “up to” $10,000. So maybe they just made the guy sign an NDA then gave him $100 and said thanks for helping us with our lying sucker, now get lost.)

    • Scrubbles@poptalk.scrubbles.tech
      link
      fedilink
      English
      arrow-up
      28
      ·
      10 months ago

      I personally love how they gave ink cartridges the ability to execute arbitrary code. Not like there are ways for them to have a signed hash or something that could do the same amount of validation, but actual code. That’s HP’s fuckup, not ours.

      • mozz@mbin.grits.dev
        link
        fedilink
        arrow-up
        13
        ·
        10 months ago

        It wasn’t quite that; there was a buffer overflow in the code that was talking to the ink cartridge. So a malicious ink cartridge could in fact take over your printer. Of course, a web page you visit could in fact take over your browser and that’s a much more realistic threat vector, and somehow we’ve survived all this time without limiting ourselves to HP-sponsored and security-assured web pages with a healthy cut of profit going to HP from every visit.

        • Overzeetop@beehaw.org
          link
          fedilink
          arrow-up
          11
          ·
          10 months ago

          in the code that was talking to the ink cartridge.

          So the flaw is in the printer or driver, and HP has just admitted to shipping an insecure, nay negligently dangerous, product to consumers?

          • Banzai51@midwest.social
            link
            fedilink
            English
            arrow-up
            4
            ·
            10 months ago

            In the 90s, they shipped recovery CDs with viruses baked in. Knowingly shipping destructive code and hardware is kinda HP’s thing.

          • Bitrot@lemmy.sdf.org
            link
            fedilink
            English
            arrow-up
            3
            ·
            10 months ago

            They all have flaws, that’s ostensibly why they also provide firmware updates. I think it’s likely their software team even fixed the original flaw while their make more money team extended it into locking down products even more.

    • Snot Flickerman@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      10
      ·
      edit-2
      10 months ago

      This is a remarkable amount of effort and money to spend trying to demonstrate the “truth” of something which everyone involved was surely aware was bullshit from start to finish.

      See the Return to Office mandates and basically anything and everything corporate-mandated. CEOs have shown they don’t actually give a flying fuck what research tells them, they’ll go with their “gut instinct” every time when their gut instinct always boils down to “Fuck you, I’ve got mine, nevermind that I got it by stealing it from you.”

      They’ll spend millions chasing thousands, they always do. The rich are only successful because of the wealth they can endlessly fall back on, the rest of us are completely fucked when we make the endless mistakes they make. It’s part of why they think they’re infallible, since their wealth insulates them from real consequences.

    • falsem@kbin.social
      link
      fedilink
      arrow-up
      5
      ·
      10 months ago

      That sounds an awful lot like even their first party cartridges could be attack vectors.

      • mozz@mbin.grits.dev
        link
        fedilink
        arrow-up
        7
        ·
        10 months ago

        Yes. I suspect that when they say the printers are only vulnerable via third-party cartridges, they mean that obviously no genuine HP cartridge would contain malicious software, therefore any malicious cartridge is by definition third party, therefore the printers are only vulnerable via third-party cartridges.