Saturday, May 30, 2026
HomeTechHP CEO Says They Brick Printers That Use Third-Occasion Ink Due to...

HP CEO Says They Brick Printers That Use Third-Occasion Ink Due to … Hackers

Final Thursday, HP CEO Enrique Lores addressed the corporate’s controversial apply of bricking printers when customers load them with third-party ink. Chatting with CNBC Tv, he stated, “Now we have seen that you could embed viruses within the cartridges. By way of the cartridge, [the virus can] go to the printer, [and then] from the printer, go to the community.”

That horrifying state of affairs might assist clarify why HP, which was hit this month with one other lawsuit over its Dynamic Safety system, insists on deploying it to printers.

To analyze, I turned to Ars Technica senior safety editor Dan Goodin. He advised me that he did not know of any assaults actively used within the wild which are able to utilizing a cartridge to contaminate a printer.

Goodin additionally put the query to Mastodon, and cybersecurity professionals, many with experience in embedded-device hacking, had been decidedly skeptical.

HP’s Proof

Unsurprisingly, Lores’ declare comes from HP-backed analysis. The corporate’s bug bounty program tasked researchers from Bugcrowd with figuring out if it is attainable to make use of an ink cartridge as a cyberthreat. HP argued that ink cartridge microcontroller chips, that are used to speak with the printer, might be an entryway for assaults.

As detailed in a 2022 article from analysis agency Actionable Intelligence, a researcher in this system discovered a approach to hack a printer by way of a third-party ink cartridge. The researcher was reportedly unable to carry out the identical hack with an HP cartridge.

Shivaun Albright, HP’s chief technologist of print safety, stated on the time:

A researcher discovered a vulnerability over the serial interface between the cartridge and the printer. Primarily, they discovered a buffer overflow. That’s the place you’ve got an interface that you could be not have examined or validated effectively sufficient, and the hacker was in a position to overflow into reminiscence past the bounds of that specific buffer. And that provides them the power to inject code into the gadget.

Albright added that the malware “remained on the printer in reminiscence” after the cartridge was eliminated.

HP acknowledges that there is no proof of such a hack occurring within the wild. Nonetheless, as a result of chips utilized in third-party ink cartridges are reprogrammable (their “code might be modified by way of a resetting device proper within the discipline,” in response to Actionable Intelligence), they’re much less safe, the corporate says. The chips are stated to be programmable in order that they’ll nonetheless work in printers after firmware updates.

HP additionally questions the safety of third-party ink firms’ provide chains, particularly in comparison with its personal provide chain safety, which is ISO/IEC-certified.

So HP did discover a theoretical manner for cartridges to be hacked, and it is cheap for the corporate to subject a bug bounty to establish such a danger. However its resolution for this menace was introduced earlier than it confirmed there might be a menace. HP added ink cartridge safety coaching to its bug bounty program in 2020, and the above analysis was launched in 2022. HP began utilizing Dynamic Safety in 2016, ostensibly to unravel the issue that it sought to show exists years later.

Supply hyperlink


Discover more from PressNewsAgency

Subscribe to get the latest posts sent to your email.

- Advertisment -