Tech,Space,Gaming, and Science Fiction News to wet your whistle
If you’re still using a fax machine for ‘security’ think again
Get link
Facebook
X
Pinterest
Email
Other Apps
While the human race, by and large, has moved on from fax machines, they're still out there. The medical and real estate industries still cling to the technology -- possibly because they believe its more secure or an easier way to get a signature from a client or patient. Well easier for them, the rest of us not so much. As for secure, turns out, that's not true.
At this year's Def Con, Check Point researchers Yaniv Balmas and Eyal Itkin unveiled how they infiltrated the HP Officejet Pro 6830 all-in-one printer/copier/fax (it was the cheapest). It's important to understand that these machines are typically connected to a network. So if that piece of hardware is compromised, it's a gateway to the rest of the computers and devices it's attached too. Since the banking, legal and medical industry still use fax machines in their offices, that's bad news.
The team encountered an impressive list of technical hurdles. The weirdest included finding out that HP's firmware was using compression software built by Softdisk and was only used once before in the game Commander Keen.
After decoding the firmware and figuring out the operating system was ThreadX. They learned that the system reads everything as a print job (even firmware updates). With that information, they constructed a JPEG (since they could tweak the header and data) file to send to the all-in-one and it belonged to them.
During the demo, they sent over EternalBlue an NSA hacking tool (aka exploit of Windows XP and above) stolen by the Shadow Brokers. The exploit actively searches a network for unpatched machines and infects them. It was the vulnerability that allowed the WannaCry ransomware to spread so quickly and cripple hospitals in the UK.
The researchers disclosed the vulnerability to HP which quickly created and distributed a fix. So if you have an all-in-one HP, you should patch it if you haven't already. But more importantly, if you or your office uses a fax machine it's important to understand that these devices are not any more secure than email.
All computers systems are prone to infiltration. A fax machine is not only connected to your network but also the outside world via a phone line. There is no firewall. Now, look at the reception area of most doctor's offices. Chances are there's an all-in-one fax machine. The real estate world is also stuck in the past. Mostly because they many require real signatures for the litany of paperwork you need to fill out to become a homeowner. There are alternatives like digital signatures. But, it's easy to see why someone would think an analog document is more secure if they are under the impression it's never connected to a computer.
It's a bit terrifying that those industries are lulled into a sense of false security because fax machines have been around forever. That's really the lesson here. Just because something has been around forever and may have originally been analog, at some point it went digital and with that convenience, there is the potential for hacking. That's the world we live in and it's important for everyone to remember that. Even your doctor.
Note-taking app Evernote has fallen on hard times of late, culminating in its latest spate of job cuts impacting 15 percent of its workforce (54 employees). CEO Chris O' Neil -- an ex-Googler who took the reins in 2015 -- announced the firings at an all-hands meeting earlier today, reports TechCrunch . In a message on the Evernote blog , O' Neill admitted he'd set "incredibly aggressive goals" for the company in 2018. He continued: "Going forward, we are streamlining certain functions, like sales, so we can continue to speed up and scale others, like product development and engineering." The layoffs follow an exec exodus just weeks ago and the company's recent brand refresh (complete with a refined logo and wordmark). But critics are more concerned about its product, especially the free tier, which they claim lacks the perks to...
By Liam McCabe This post was done in partnership with Wirecutter . When readers choose to buy Wirecutter's independently chosen editorial picks, it may earn affiliate commissions that support its work. Read the full article here . After six summers of researching, testing, and recommending window air conditioners, we've learned that quiet and affordable ACs make most people the happiest—and we think the LG LW8016ER will fit the bill in most rooms. This 8,000 Btu unit cools as efficiently and effectively as any model with an equal Btu rating, and runs at a lower volume and deeper pitch than others at this price. Little extra features like a fresh-air vent, two-axis fan blades, and a removable drain plug help set it apart, too. The LG LW8016ER is a top choice for an office or den, and some people will find it quiet enough for a bedroom, too. If our main pic...
Pre-loaded cartridges of cannabis concentrate are currently among the most popular means of consumption, and for good reason. They're discreet to use and easy to handle, a far cry from the dark days of 2016 when we had to dribble hash oil or load wax into narrow-mouthed vape pens by hand. But, frustratingly, an ever increasing number of oil cartridge manufacturers employ one-off design standards so that their products won't work with those of their competitors, thereby locking customers into proprietary ecosystems. We've already seen this with nicotine vaporizers -- which has a seen a massive rise in "pod systems" in the last few years, each outfitted with a unique canister and battery built to be incompatible with those of their competition. Is it too late for the burgeoning cannabis industry to set a universal standard for their product designs? ...
Comments
Post a Comment