HP bug bounty in place to assist determine safety flaws of their printers
von Satoshi Nakamoto

However don’t get too excited simply but: the first-of-its-kind bug bounty program for printers is invite-only for now
Researchers can earn as much as $10,000 for figuring out safety flaws in printers made by HP in what's the first bug bounty program aimed particularly at printers, in keeping with an announcement by the tech large on Tuesday.
The payouts will rely upon the severity of the flaw found, and HP might also make a “good religion fee” for reporting a vulnerability that the agency has recognized earlier than. Safety Week stated that the researchers have been informed to hone in on firmware-level bugs.
HP’s initiative is a nod to the truth that safety threats transcend computer systems to incorporate any gadget related to a community. Certainly, internet-connected printers generally is a critical safety legal responsibility. Attackers can't solely steal delicate knowledge from them or coerce printers into revealing customers’ administrator passwords, however they will additionally use the gadgets as jumping-off factors for additional compromises of networks. Printers can be corralled into botnets, as has occurred with Mirai.
HP highlighted its dedication to making sure the very best degree of printer safety so as to reduce the chance of such threats. “As we navigate an more and more advanced world of cyber threats, it’s paramount that trade leaders leverage each useful resource doable to ship trusted, resilient safety from the firmware up,” HP’s Chief Technologist of Print Safety Shivaun Albright was quoted as saying. “HP is dedicated to engineering essentially the most safe printers on this planet,” she added.
Darkish Studying wrote that HP’s concentrate on printer safety can also be as a result of – in comparison with flaws in different Web-of-Issues (IoT) gadgets – vulnerabilities in printers have usually been on the again burner. “There’s a giant concentrate on related gadgets like Internet cameras or good TVs, that are extremely relatable to everybody, however not printers essentially,” Albright was quoted as saying. “That stated, printers could also be the most typical IoT gadget a person makes use of.”
In the meantime, CNET quoted Albright as saying that the bug-hunting program had truly been quietly launched in Might. Thirty-four researchers signed up again then, and one in every of them has already obtained $10,000 for locating a critical loophole in HP’s printers. This system is invite-only, in order that it permits for simpler administration of incoming vulnerabilities. HP goals to make this system public sooner or later, nonetheless.
The initiative is backed up by safety crowdsourcing firm Bugcrowd, which can handle the vulnerability reporting and verification, in addition to deal with which researchers are invited to hitch. HP additionally quoted the agency’s current report, which acknowledged that the entire print vulnerabilities throughout the trade have elevated 21% through the previous 12 months.
The researchers who've been chosen to take part within the initiative have been supplied with distant entry to 15 printers, that are remoted in HP’s workplaces. “From their computer systems at house, they will poke at and pry into these machines to seek out hidden vulnerabilities,” wrote CNET.
Tomáš Foltýn 1 Aug 2018 - 02:27PM
(function()
var _fbq = window._fbq )();
window._fbq = window._fbq || ;
window._fbq.push();
(function(d, s, id)
var js, fjs = d.getElementsByTagName(s);
if (d.getElementById(id)) return;
js = d.createElement(s); js.id = id;
js.src = "http://connect.facebook.net/en_US/sdk.js#xfbml=1&version=v2.3";
fjs.parentNode.insertBefore(js, fjs);
(document, 'script', 'facebook-jssdk'));
Source link
Read the full article
Satoshi Nakamoto
Keine Verbindung
Verbindung wird wiederhergestellt
Etwas ist schiefgelaufen
Wir sind gleich wieder da