Also somewhat depressingly, HP is definitely the most secure printing company. That's not a very high standard though. But what it means is everything these guys have found...is much worse worse at every other printer company. HP was the first printer company to join HackerOne I believe, shockingly they still make some of their server brands in the US, and the security options on their entry level enterprise printers (m406) show at least some effort was put into them (for instance only allowing SNMPv3).
Yet at the same time, why can I only have a max 16 character password on the web management portal? Why does the username have to be "admin" which is obviously super easy to guess?
NOTE: I first saw this article as a promoted tweet on Twitter. This was hilarious to me because it was the first time I had had a relevant promoted tweet shown to me where I also didn't feel like the party involved was being misleading in some sort of way.
EDIT: Had trouble accessing their site. Some things to note that they found:
- Why do you have to download the updates manually from HP? Why can't the printer check? Why is it not automated? This process is awful. Do you then upload the zip file of the update to the printer or the bin file inside, or is it the bin file plus the md5 hash?
- PCL and PJL are languages that predate IP. Very insecure and so many things that have never been fixed.