Risk
8/10/2010
12:36 PM
50%
50%

Xerox Advises Securing Data In Printer Hard Drives

Network printer and MFP hard drives may contain sensitive data that can be secured using encryption or overwriting.

"The risk is that after a job is done, MARCed and printed, there may be some residual data left behind associated with that job," says Kovnak. And, as with computers, even if the system "deletes" a file, that doesn't actually remove file contents, just frees up those spaces on the disk for re-use, so if a large print job that contains sensitive data is followed by a smaller print job, some sensitive data might still be on the drive.

Also, Kovnak points out, "Some of our more complex devices let users store jobs for later reprinting, or to hold the job until the user arrives and requests the file" (so that it won't be sitting around where an unauthorized person can read or take it).

As with computers, says Kovnak, there are two ways to counteract the risk of that data being accessible: "Encryption, which protects the data while it's still in use, and overwriting, after a job is done."

How can you tell if your printer or MFP could have data at risk?

"It's hard to tell just by looking whether a device has a disk," Kovnat points out. "If it's a device you already own, you have to check the product description. SMBS can the vendor representative."

According to Kovnat, many Xerox devices include both encryption and overwrite. "The encryption feature in most of our devices is enabled by default; the overwrite is not enabled by default," says Kovnat. "For most of our products, they're now standard, but they may not be turned on."

Xerox also offers data security features that can be downloaded, for some machines -- but, he cautions, "for older products -- ones introduced five or more years ago -- these features may not be available."

Previous
2 of 3
Next
Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-7830
Published: 2014-11-24
Cross-site scripting (XSS) vulnerability in mod/feedback/mapcourse.php in the Feedback module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the mod/feedback:mapcourse cap...

CVE-2014-7831
Published: 2014-11-24
lib/classes/grades_external.php in Moodle 2.7.x before 2.7.3 does not consider the moodle/grade:viewhidden capability before displaying hidden grades, which allows remote authenticated users to obtain sensitive information by leveraging the student role to access the get_grades web service.

CVE-2014-7832
Published: 2014-11-24
mod/lti/launch.php in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 performs access control at the course level rather than at the activity level, which allows remote authenticated users to bypass the mod/lti:view capability requirement by vi...

CVE-2014-7833
Published: 2014-11-24
mod/data/edit.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 sets a certain group ID to zero upon a database-entry change, which allows remote authenticated users to obtain sensitive information by accessing the database after an edit by a teacher.

CVE-2014-7834
Published: 2014-11-24
mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not verify group permissions, which allows remote authenticated users to access a forum via the forum_get_discussions web service.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?