HP rushes to fix bricked printers after faulty firmware update
bleepingcomputer.com
bleepingcomputer.com
Now the world evolved to the point that patches shamelessly remove features or install adware. Even the big names are incompetent enough to cause damage on a regular base. Meanwhile, the internet learned to deal with botnets as a fact of living.
So, assuming you live in a country where identity theft isn't much of a problem, and assuming regular and working backups are implemented, I start to wonder if it isn't time to review our best practices: Don't allow anything on the internet unless it really should (get a good enough firewall), don't run as root or administrator unless you have to, but also disable automatic updates, and do manual updates when a patch is out for 2 weeks and has proven not to cause more trouble than good.
So what's your opinion? How should a non-techy deal with today's landscape?
Preposterous amount of time spent to make sure I don't end up with "bing discover" feature that some product manager rammed through into the Edge or reset my settings because microsoft reaaaaly wants my new tab page for ad revenue. Oh look latest windows release has "microsoft rewards" in every frequently-viewed UX component; wonderful.
There's an army of CVE bros cargo-culting bullshit like "it doesn't work if it's not auto up to date", when the reality is the product doesn't work if the latest upgrade breaks my workflow or I have to stop what I'm doing and spend a bunch of time undoing whatever new "feature" got added for user-adverse but revenue positive purposes. I don't think I've seen an update in the last 5 or so years that didn't try to turn a thing that I own into a grocery checkout aisle for other stuff that I should own.
My HP printer sits behind a NAT and a firewall and the firmware has been feature-complete since they built the stupid thing. The only thing you get with upgrades is operational risk; hedging imaginary "someone's gonna p0wn it" problems is the security equivalent of the $5 wrench XKCD.
Richard Stallman’s positions on software seem less extreme every year.
Ask 1990s or 2000s me, and I’d say he was interesting but “out there”.
Now, I’m thinking he was just 30-40 years ahead of his time.
I see the big fight now is over AI. The talk is over AI ethics and safety … but can we honestly entrust that to Big Tech?
The reality is they simply cannot, and won’t. While safety will (probably) be assured, because unsafe products bring lawsuits, unethical products that extort customers for money are apparently perfectly legal. We see this in pharmaceuticals, processed foods, and of course Big Tech.
But requiring licenses to construct or deploy AIs would be a sufficiently large moat.
I should have control over model updates, retraining, the training pipeline, the prompts... Everything. How ethical or safe the ai is is my problem. It's not a matter of trust, but that it gets changed out from under me, breaking my workflows, and not letting me fix problems with it that affect me.
Is there a lesser of two evils here? I honestly don't know, but I don't think we will get a choice.
Would that even work on an Apple device?
Yupp and it's way easier to do - launchctl list and blow away what you don't want without the bs of looking at registry, then group policy, then domain controller nonsense, then services, then start up items then...
And then backpedal furiously and say that it was "a temporary measure while some apps were getting fixes and updates". Huh - not sure why TextEdit.app ever needed a kernel extension but maybe they're right, and it wasn't just a BS excuse.
You should more or less _never_ update your 'dumb' devices unless there is a specific feature/bugfix you need.
Is your lan not connected to the internet?
For non-techy home or SOHO users, they're likely using smtp.gmail.com with their gmail creds though. Would not be unresonable to dedicate a gmail account just for scan to email IMHO.
That's exactly what I'm worried about. Obviously there are ways to do it safely (and gmail actually I think might even force them), but I have very low expectations of a lot of the userbase (not a dig at them: the tech isn't exactly set up to make the easy thing safe).
So yes, in that case I'd rather that this app literally never ever changed - there was nothing wrong with it, but of course some designer somewhere has to justify their continious employment so they roll out these interface changes to basically have a job. I'm sick of it.
These are gigantic assumptions. I am not exaggerating when I say gigantic. Identity theft alone is hitting record highs in the EU in both percentage affected and money exploited.
The other problem is we tend to offer advice that is so vague it might as well be harmful. What does it mean for a patch to be proven to not cause more trouble? How does one prove a working backup? List goes on. We wind up giving so much of this nice sounding but useless advice that we confuse people. Even techies! You see it on HN all the time, bad/mediocre advice passed around and internalized, things regurgitated because it sounds good not because it's what will keep your data safe.
When advice is so horrible even techies wind up reverting to the most simplistic solution possible, that's a very clear sign we are doing a horrific job!
Also: What is your alternative? I hate my own post above, but can't really think of anything better.
I also don't think your post is to be hated, it is not bad and is actually important in getting people on board with the idea of mass reinvention of digital services. We can't get there until we all accept that digital life currently is just far too invasive and we need better regulation before we can even start to work on personal advice. Such personal advice from Telekom[1] as an example, most of it sounds good but doesn't actually work in reality due to how weak our data privacy laws are.
[1] https://www.telekom.com/en/company/data-privacy-and-security...
I've had two laptops bricked by faulty windows 10 updates in the past. I've gone through the whole gauntlet of people trying to gaslight me with statements such as "It is impossible for a windows update to brick your computer, or get stuck in an infinite updating loop."
I advise pretty much everyone I know to avoid updating important software automatically. Updates for critical software or hardware should only be done to a specific version that has been out for at least a month. Even then, always check multiple sources to ensure it won't introduce something unwieldy.
But of course, that gets a bit tedious for some people. So generally I only apply it to non-security updates, hoping and praying Microsoft hasn't screwed the pooch again with one of those. (Which has happened in the past.)
I did this after chrome’s auto update checker (not the actual update) pegged my cpu to 100% enough times that I rage deleted the updater. Then chrome kept rewriting it and undoing my settings to not update.
It’s a risk I run but chrome lost my trust.
Safari auto updates without ever causing me to notice.
Throw away any tool you do not know how to use. Get off the internet. Get off the computer. Revert 30 years (or more) of progress because we clearly went wrong somewhere.
Even that isn't enough, many a botnet has employed lateral movement inside a network.
Manufacturers will simply ship dormant changes that wake up a month after deployed.
I've had much better experience with Brother.
My Brother printer no matter what I do likes to go into this deep sleep mode that may as well be powered off, nothing wakes it up, power cycle and it drops right back into deep sleep immediately.... The software for it is bulky, wants to run on my PC all the time (why?).
Is it better than an HP printer, yeah probably in some sense, but the landscape of printers all being a pain is still true.
I don't have a functional printer right now. I need one ... but I keep procrastinating buying one. I just don't want to deal with it.
I'm sure that, like any other company, they have better and worse products -- but I did very little research on this, bought to price point, and have been very happy. Certainly not the HP experience.
If your printer is not waking up from deep sleep, I've found it due to poor multicast support on your network. I've had to debug various issues related to waking/discovery and once I resolved the multicast issues this problem went away. Specifically I ran into a UniFi bug with mesh networking and this problem is significantly exacerbated by poor mesh networking equipment.
Brother printers rarely, if ever, need the full software suite and they indeed have a "driver-only" install available most of the time.
Give the printer its own fixed IP address by specifying the MAC address in the router's DHCP table.
Certainly not except for the few dedicated internet PC's handled by IT for email, browsing and company-wide office apps. Those have so many layers of hardware firewalls and other passive & active security it's not easy to get as much office work done as in earlier years, but we work around it.
In my chem lab with all those expensive (some vintage) scientific instruments, I air-gapped ASAP when I came on board. I have made lots of scientifc progress but the most valuable thing I've done for my employer is kicking IT out of the lab. 100x reliability after that, averaging less than a single need for attention per year.
Here's something I just found out recently.
Had one of the Windows 10 2019 vintage (installed from unpatched ISO) PC's on my isolated local XP network, where a very old Lexmark non-network USB/parallel printer on an XP workstation was just a regular USB printer being shared with the rest of the LAN by XP.
The Lexmark was a business machine installed with 32-bit XP drivers which were available in about 2016, which was about the latest it was supported, which support ended with Windows 7.
Luckily it turned out I had chosen the PCL6 version of the drivers.
When I had added the 2019 W10 PC I had naturally used a 32-bit version since this one does not need to use more than 3.2GB of memory at all. With the local LAN & W10 configured (not so easy) so W10 could easily access the Lexmark shared by XP, upon first connection W10 requests the Lexmark drivers before it will proceed. I used the W7 PCL6 drivers and everything was just fine for years.
Unfortunately the Lexmark tragically succumbed to an untimely death before it reached its 21st birthday.
Then I was able to select a consumer-grade new Brother USB/LAN/Wifi unit having a model No only available from Walmart (over the last few years since release) as the best bargain. Only an inconsequential distinguishing feature difference from the non-walmart generally available equal-printing-performance machine. It's another whole story but was out of stock for $89 with no sign of restocking, appearing discontinued and replaced by a new equivalent model for $139. I knew people must have bought quite a few at $89 before they were all "gone", and could see lots of them NIB for $139 on Amazon. I dug in and found a refurbished (designated 1 item remaining in stock) for $79 and it arrived shortly from walmart.com. Looked like a NIB return with a refurb sticker on the back. There was still "one" remaining in stock for weeks after that when I checked. Hmm.
Never uninstalled the Lexmark drivers, just plugged Brother into USB of the XP PC, used the Brother W7 driver, and worked like it should on XP, shared with the local LAN no differently than the Lexmark had been. Office manager and IT couldn't believe I got a brand new printer to just drop-in to my decades-old XP network when it was not officially supported for XP.
Newer W10 & W11 ISO's were used on a couple new local workstations but these were so new they were already sporting the "Print Nightmare" "upgrade" so no shared network printing for you. Oh, well. Turns out, naturally you can't use the printer's LAN connection simultaneously with its Wifi, but I wasn't actually using either, just USB. And the Wifi-Direct option worked just great[0] to connect to one of the new W10/W11 PC's on an individual ad-hoc basis as needed and everything was well from those wifi PC's and laptops when they needed to occasionally print. No Wifi-Direct conflict with the USB connection shared by XP over the local LAN at all.
Now I don't actually use the instrument the 2019 W10 PC is connected to very often and was occasionally printing from it over the shared XP LAN for a number of months before I recently remembered I had never installed any Brother printer drivers at all, never even made an explicit request to connect to the Brother on the shared LAN like I had to do when I first got the Lexmark going. Double-checked and nothing but Lexmark as default printer on that W10 PC.
Brother just worked. Really dropped right in in this regard.
PCL6 FTW.
[0]>likes to go into this deep sleep mode
If asleep, must be woken up from the main wired LAN the USB printer is sharing, before connecting a session of Wifi-Direct.
Edit: you may be able to set the sleep delay from the printer keyboard.
No drivers necessary either way.
One more thing, when W11 was released, the Brother website said they would have W11 drivers within 60 days or so. Showed up early and were the exact same driver files used for W10 the last few years.
Is the company aware of why they’re so loved/respected these days?
So far the performance has been rock-solid across several Linux and macOS machines and I almost forgot the saying "printers sense your fear and will break at the worst possible moment".
I think the solution should be something like the EnerGuide labels that reveal the long-term cost. Then customers would be able to tell that this cheap printer sold at a loss will have crazy expensive ink.
I finally got fed up with it a few weeks ago and bought a Brother printer.
[1] https://twitter.com/search?q=printer+from%3AFrameworkPuter&f...
If you have any kind of electronic device that gets bricked by the manufacturer via firmware update after warranty.
If the manufacturer decides to just do nothing (unlike HP which is trying to fix things here), what happens? Do customers have no recourse? Or do they sue the company individually? Or does it become a class-action suit? Or does it not go through the courts at all, but is there a regulatory body that fines the company for the value of the devices plus a punitive fine, and then distributes money or replacement devices to affected consumers?
Not asking what should be done morally, but what the law actually says?
That negates basic contract law to a degree that I think that it already is illegal.
HP didn't brick any machines because of ink choice. They prevented them from working with off-brand ink, but the printers worked properly again once HP ink was inserted. "Bricking" is permanent, but the ink thing wasn't. "Bricking" was a disappointingly widespread misconception in the thread from 7 days ago:
https://news.ycombinator.com/item?id=35931468
Again, I'm not condoning the ink thing at all, but "bricking" is not what was happening. HP is already bad enough, we don't need to spread false information on top of it.
Your printer may work but now it's almost cheaper to throw it away and buy another one than refilling it. The only way it could be worse would be if HP decided to triple their ink price the same day.
If BMW updated and locked your car unless you used BMW branded wiper fluid (i.e. water) they'd be sued and scorned all the way to outer space, but somehow when a printer company does it it's okay.
It either is or it isn't.
They're not going to replace it because there's a fix coming "soon"
This might explain it.