They use the small flash inside the DRM chip in the cartridge to store the telemetry, then the e-waste companies are paid by HP to read and send to the mothership the contents of the chips sent to recycle

you are viewing a single comment's thread
view the rest of the comments
[–] 20 points 11 months ago (5 children)

Isn't the point that a hacker can use that memory to export other data?

  • source
  • parent
  • hideshow 5 child comments
  • [–] 0 points 11 months ago (3 children)

    You'd first need to get the flash to store other data, requiring malicious firmware modifications.

    Like, its not impossible but I really can't see anything nefarious happening to make airgapped printer that would be that big a deal.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 5 points 11 months ago (2 children)

    Lets say a malicious actor infiltrates the supply chain and loads custom firmware on the device. Somehow the malicious firmware avoids detection, and is installed in a secured environment.

    What can be exfiltrated in the flash is probably pretty limited, but top 5 usernames and their top 5 IP-addresses, perhaps as many jobtitles as can be stored correlated to the above information. And now the attacker can extrapolate all sorts of classified information.

  • source
  • parent
  • hideshow 2 child comments