Summary is AI-generated, newsdesk-reviewed
  • Bomb threats show university printer security vulnerabilities.
  • Secure network printers with passwords, restricted access, and disabled services.
  • Compromised printers can attack networks, and execute malicious code.

Colleges and universities have been targeted in the last several weeks with a series of bomb threats received via campus printers and fax machines. Targeted institutions included Vanderbilt University, the University of Southern California, the University of Virginia and the University of Detroit Mercy, among others.

Businesses were also among the targets. Around 100 organizations in all received print-outs, faxes or emails demanding that a $25,000 ransom be paid to a Brazilian citizen to avoid detonation of explosives allegedly planted on the sites. The police determined that the “form letter” threats were part of a hoax and not credible.

The situation highlights the need to proactively secure access to printers in today’s networked world. SourceSecurity.com asked Ashish Malpani, Director, Embedded Solutions Product Marketing at HID Global, for insights from a technology perspective.

SourceSecurity.com: What are the best practices for securing access to a printer? How widely employed are such practices (i.e., how vulnerable are most printers today?)

Ashish Malpani: Most network printers in university environments are secured using several best practices. They include:

  • Set a strong administrator password. Modern MFPs (multi-function printers) have a web interface for configuration and control. By default no password is set so it is important to set a strong admin password.
  • Restrict network access to campus. Ensure that only campus IP addresses are able to access the printer.
  • Disable unnecessary services. Disable services like FTP, Telnet, other network (and discovery) protocols, etc.
  • Implement firmware updates.
  • Securely dispose of MFPs.

A recent scan at University of Nebraska at Lincoln found that, in spite of all security practices, 12 percent of printers still have open port and password issues.

SourceSecurity.com: How can systems be set up to accommodate students who need access to printers from off campus (or outside the firewall)?

Malpani: In the university environment, the need for off-campus print access is prevalent. One of the ways to enable this capability is to force students to connect to the university network using a virtual private network (VPN). However, this is inconvenient and doesn’t usually support printing on demand or printing from handheld devices and cloud storage.

An effective way to address this issue is to deploy a secure printing solution, where the users are required to authenticate themselves before the print job is released to the printer from a centralized pool. The benefits of this approach are increased convenience and ability to print at any printer on the campus. However, most printer manufacturers support entering a PIN for authentication, and it is not necessarily secure or convenient when you want faster access. However, new innovations in secure printing have made the printers more identity-aware and rely on everyday devices such as cellphones and wearables for authentication, resulting in secure and convenient access.

SourceSecurity.com: Whose responsibility is the security of a printer? Should manufacturers be doing more to prevent unauthorized access to printers? What is the customer's role?

Malpani: IT security staff is responsible for the security of the printer. Something as simple as a printer is expected to work right away after deployment. Manufacturers can do more to enforce security policies on the printer or provide modes that enforce stricter control by default. As a customer, it is critical to have print data security as part of security policy, to review the manufacturer’s recommendations for securely configuring a printer, and to find solutions that not only enhance the security but also provide convenience to end users.

It is critical to develop a comprehensive security policy and regular audit schedule to secure printers
A compromised printer can be used to attack other applications, execute arbitrary malicious code or attack other systems

SourceSecurity.com: What are some other ramifications of unsecured printers, beyond the printing of threatening materials as we have seen recently on college and university campuses?

Malpani: Today’s MFPs are more than just printers. They are file servers, they can email, act as DHCP (Dynamic Host Configuration Protocol) servers, and have the capacity to hold large data sets. Unsecured printers risk misuse and data disclosure. In January of this year, a team of researchers from Ruhr-Universität Bochum in Germany exposed vulnerabilities of major MFPs, such as exploiting the PostScript and Printer Job Language (PJL) vulnerabilities to get access to the data on the printer’s files system and memory.

SourceSecurity.com: How does the problem of unsecured printers relate to wider issues of network security (given that most printers are now networked)? What is the risk that printers might be vulnerable as an entry point to the larger network?

Malpani: In addition, a compromised printer can be used to attack other applications, execute arbitrary malicious code or attack other systems (e.g., to launch a denial of service attack on the network).

SourceSecurity.com: How does the risk of unsecured printers impact the business world or other markets (in addition to college campuses)? How are the security measures different in various environments?

Malpani: The security challenges are the same in business environments but, other than the financial industry, most other businesses do not pay close attention to threat vectors emerging out of print data security. IT security departments are also concerned about network security, and the facilities worry about building security, paying little attention to the security of business systems like printers, elevators, HVAC systems etc. Businesses are increasingly turning to managed print service (MPS) providers to ensure compliance, data security as well as management of accessories like print cartridges.

SourceSecurity.com: What's your best advice for customers in terms of what they should do to secure their printers?

Malpani: First of all, know your customer, understand their needs and what capabilities they desire from the printing systems today. The next generation of students value convenience over privacy and security. So the IT departments across universities need to think about how to meet the needs of their customer while ensuring best practices for security and compliance.

It is critical to develop a comprehensive security policy, a regular audit schedule, to secure printers according to manufacturer’s recommendation, and to invest in solutions like secure print that not only provide convenience but also enhance security. Identity-aware systems definitely handle the challenges more effectively than traditional practices going forward. So it is important that the solutions we invest in also take into account the future trends in authentication and printing.

How strong are your company’s defenses against cyber threats?

18.2%

50%

22.7%

9.1%

HID news

ISC West 2019 Day Two: Explaining The New And The Tried-And-True

There are many new technologies at ISC West this year. There are also some tried-and-true solutions on display. More mature products have the benefit of being fully vetted and battle-tested, which may make them a more comfortable choice for security customers. I had a couple of discussions on Day 2 of the show about the advantages, and possible drawbacks, of new products. “To a security director, when you say ‘new,’ he translates that into ‘risk,’” says Bill...

How Is The Role Of Biometrics Changing In Physical Access Control?

Biometrics today provide better security and frictionless user experiences. Biometric identifiers like fingerprints, facial recognition, and iris scans are unique and difficult to forge. They eliminate the vulnerabilities of traditional authentication and streamline secure access control. Identity verification reliably protects sensitive digital information and physical entry. We asked our Expert Panel Roundtable: How is the role of biometrics evolving in physical access control?

HID Signo Décor Reader For High-Design Spaces

HID, a worldwide pioneer in trusted identity and physical access control solutions, has launched HID Signo Décor in response to a request that architects, specifiers and integrators have repeatedly raised: a Signo-grade reader built for high-design spaces, without a compromise on the security behind it. The Signo Décor Reader 30 model mounts flush on European- and China-style back boxes and sits behind a robust glass face, rated IK10 for impact resistance and IP65 for indoor and o...

HID case studies

HID Helps In Automating The Access Control Management At Żabka

Enhancing enterprise security is high on the list of priorities for businesses across sectors. Within the retail industry, there is an additional focus on enabling new ways of working through management tools. Integrated solutions and applications help to create a robust security landscape and ensure a future-ready posture as organizations look to address emerging risks and create better experiences for next-gen employees. Physical access control (i.e., the readers on the door and the credentia...

HID And Kodaa Transform 101 Collins Street Access

HID, a pioneer in trusted identity and access control solutions and Kodaa, an Australian digital consultancy, announces that Melbourne’s iconic 101 Collins Street tower is emerging as a live example of how mobile credentials are moving from pilot projects to everyday building operations - with thousands of tenants and visitors now accessing one of the city’s most prestigious commercial towers through their mobile wallet, without the need for a physical card. The Collins Street build...

BNY Innovates With Mobile Access Solutions

How do you rethink and transform building access for a 241-year-old company? BNY started by asking employees. The response was encouraging. The BNY team found that employees embraced the concept of mobile access solutions. The thought of implementing access solutions was already being considered by the company and the team was excited about the idea of providing a modern experience that allows employees worldwide to conveniently access their building spaces with a simple iPhone or Apple Watch....