Is your office printer secure?

Network-attached device security poses serious risks, warns ISCA Labs

  • Email to a friend
  • Print this article
  • Bookmark this page
  • RSS feed

Hackers may be using your office printer as a conduit for criminal activity. Think about it: A printer in today's office environment often saves on its hard drive all images of documents that are printed, scanned or faxed. Therefore, hackers who know anything about accessing files on a network might easily gain access to that sensitive data.

This kind of threat is too frequently overlooked, according to ISCA Labs, a security products testing and certifications firm.

ISCA said Monday it is introducing new certification and assessment programs that will address security threats posed by networked devices such as printers, fax machines and security cameras, will include a vendor certification program. The class of network-connected devices addressed by the program will include printers, faxes, point-of-sale systems, copiers, ATM machines, digital signs, proximity readers, security cameras, and facility management systems for power, lighting and HVAC systems, said George Japak, managing director, ISCA Labs.

How hackers find your weak spots

"You have UPS systems, you have power strips, I could go on an on about the different devices that are being connected with this functionality"

Network-connected devices, according to Japak, can pose as much risk as an unsecured server on the network but are often ignored and are typically not securely installed or configured by end-users, he said. Network-attached devices, like network servers, are at risk for unauthorised access and data breach, denial of service attacks and can even propagate worms like Code Red Nimda.

However, specific statistical data to back up the severity of the security issues posed by network-connected devices is scant. ISCA referred to figures from the Verizon Business 2009 Data Breach Investigations Report which finds many breaches occur through what is called "unknown, unknowns," which can involve systems such as printers and faxes. No further data about specific attacks or incidents was available from ISCA.

"Based on the feedback from current and prospective customers, this is going to be or have the potential to be a significant issue and problem with enterprises as they continue to deploy these devices," said Japak.

Networked-device security is certainly not a new issue and the potential for security problems with devices has been talked about for several years now. Printer security has also received attention from other organizations.

Earlier this year, the IEEE released new security standards for networked printers that include specifications and a checklist for printer security requirements. The standards, known as the 2600 Profile requirements, were created by IEEE in a joint effort with Xerox and were created to give printer vendors basic security requirements when developing devices. Japak said ISCA is still reviewing the IEEE standards to determine who they will fit in with the NAPS program.

The NAPS certification will target device manufacturers and will include rigorous testing that examines several different aspects of a device and how each impacts its overall security. ISCA is also hoping to gain attention from enterprise clients concerned about device security with a NAPS assessment program that offers an evaluation and report with results of testing and recommended configuration instructions.


Contact Us

For editorial queries:
Max Cooter max_cooter@techworld.com

For website issues:
Email webmaster@techworld.com

For commercial queries
Russell Kearney russell_kearney@idg.co.uk


For more contact details click here.

What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.


Characters remaining: 500

Add your commentComments

Richard Skinner | Published: 13:56 GMT, 01 March 2010

Great, informative article, the security can be quite a worry on certain photocopiers. Top4Office are a UK dealer of photocopiers for well known companies such as Ricoh, Canon and Toshiba. They give some brilliant advice and confidence when purchasing photocopiers as well as other office machines like printers, multifunctionals, fax machines. Top4Office also have a brilliant range of copiers to choose from to meet your requirments. Visit their website at Top4Office

Related Security news

Hackers offered $100,000 for browser and phone exploits

Under attack at TippingPoint's 'Pwn2Own'

Cisco battered by large fall in security market

Rivals scoop up customers in Q4

Child porn blocked by new 'fingerprint' system

Uses police database of 400,000 images

Zeus malware now has Windows-like piracy protection

Hackers lock DIY botnet software to single PC using product activation code



Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Email archiving: Top 10 myths and challenges

This survey looks at a number of challenges and myths around email archiving that may also slow adoption of full archiving.

Download Whitepaper

Strategic mobile deployments

Deploying mobile applications? Supporting multiple devices? See why mobile platforms should be part of your IT strategy.

Download Whitepaper

Creating an AUP: Common myths & mistakes

Avoid the common myths & mistakes when implementing your AUP

Download Whitepaper

Legal risks of uncontrolled email and web use

Exploring the challenges facing IT Mangers today and vital steps to ensure safe internet an email use by employees.

Download Whitepaper

Techworld UK - Technology - Business

COLT White Paper

Virtualisation 2.0
Driving to higher ground beyond the basics

Virtualisation can deliver unparalleled efficiency and cost reductions to your business, allowing direct access to servers and guaranteeing a dependable, rapid response in times of crisis. Read this e-book to learn more about consolidation, discover the latest technologies and find out how to reduce the TCO of virtualisation.

Download E-Book
COLT White Paper

IT Misuse Survey

Complete this survey and you could win a Nexus One

Techworld are running a short survey to discover how UK businesses are managing Internet and email misuse in the Enterprise.

Complete Survey

Webcast: IT Financial Management: Cost Optimisation for Efficiency and Agility.
On Demand Webcast
Join this webcast to learn about the techniques and technologies that can help you prove the value of IT to the business by understanding the true cost of today's IT services and those that will be necessary to deliver future success.

Register Today

Site Map

IDG Network

* *