Live data from Hacker News

Pwning a Brother labelmaker, for fun and interop

sdomi.pl

41–50 of 50 posts

Re: Pwning a Brother labelmaker, for fun and interop

#42

I realized after finishing a reel in a label maker that some have a negative film type reel to them that discharges when printing. Before throwing it away, I looked at it and it contained classified information.

> it contained classified information.

Is that like the way that, in the days of typewriters, government people typing highly-sensitive information would sometimes burn the typewriter ribbon?

Re: Pwning a Brother labelmaker, for fun and interop

#43

Earlier quoted context omitted.

I was about to buy a D610BT or P710BT (to use on Mac) ... what enshittification should I know about?

I think the protocols for those are reasonably well understood, but e.g. you can only print via USB from a Mac, Bluetooth was only on a phone AFAICR

Been printing on my D610BT from my Mac via BT since I got it. Very handy as I don't need to fumble for a cable anymore.

Re: Pwning a Brother labelmaker, for fun and interop

#47

Earlier quoted context omitted.

If plausibly your label printer is an attack surface of significant consequence, a Dymo is the simplest thing that might work. https://www.staples.com/dymo-organizer-express-pro-industria...

I feel a bit silly being excited about this, but of course there's a circa 50s office solution that requires no batteries and electronics. I don't know what I was thinking!

I didn't mean to make you feel silly, sorry. Dymo was the logical extreme of my concern regarding security architecture.

What I mean is there are three vectors for attacking a label printer: physical access, local network access, and internet access. If an attacker has physical access, your problem isn't the label printer, it's physical security. If an attacker has local network access to your label printer, your problem isn't the label printer it's network security.

There are use cases where internet access is worth a security risk. In that case, device choice should reflect the risk. Consumer hardware has a different risk profile than commercial hardware. Enterprise hardware has a different profile too. Same with custom bespoke solutions from consultants.

Updating the kernel on a consumer device typically means connecting the device to the internet because an internet connection is the most consumer friendly way to update it. For consumer devices convenience is generally more important than IT security.

My gut reaction that led to my response is that security requires engineering analysis of budget, risks, and rewards. Hardening the Linux kernel of a Brother label printer isn't better engineering because the IT problem it addresses is more fundamental. Again, sorry for making you feel silly. It was not my intent.

Re: Pwning a Brother labelmaker, for fun and interop

#48
I have a three year old Brother laser printer and for the longest time, I had problems using the wireless printing feature. My laptop would recognize the printer, install it but fail to print. Only using the USB cable it would work. Three months ago, I found the printer web UI using nmap and found there was an ‘update’ with a date of 2020 on it (so before I bought the printer) and I installed it and wireless printing now works flawlessly :-)

Re: Pwning a Brother labelmaker, for fun and interop

#49

Earlier quoted context omitted.

I feel a bit silly being excited about this, but of course there's a circa 50s office solution that requires no batteries and electronics. I don't know what I was thinking!

I didn't mean to make you feel silly, sorry. Dymo was the logical extreme of my concern regarding security architecture. What I mean is there are three vectors for attacking a label printer: physical access, local network access, and internet access. If an attacker has physical access, your problem isn't the label printer, it's physical security. If an attacker has local network access to your label printer, your pro…

Oh I'm sorry, I didn't mean it like that - I just meant as in feeling so excited like a child over what amounts to a manual labelmaker :-) No bad vibes at all on my end though. Very interesting about the rest though, thanks for the comment.

Re: Pwning a Brother labelmaker, for fun and interop

#50

Earlier quoted context omitted.

I didn't mean to make you feel silly, sorry. Dymo was the logical extreme of my concern regarding security architecture. What I mean is there are three vectors for attacking a label printer: physical access, local network access, and internet access. If an attacker has physical access, your problem isn't the label printer, it's physical security. If an attacker has local network access to your label printer, your pro…

Oh I'm sorry, I didn't mean it like that - I just meant as in feeling so excited like a child over what amounts to a manual labelmaker :-) No bad vibes at all on my end though. Very interesting about the rest though, thanks for the comment.

They are cool and I almost bought one, that's why Dymo's were mentally at hand.

Instead I bought the cheapest Brother on Amazon...it doesn't connect to the internet, just sits in a drawer. Maybe if I come across a Dymo in a thrift store, I'll have one too because they are kind of cool.

Which reminds me, about 25 years ago I had a Kroy 80 in my studio. The Kroy 80 is a Dymo on steriods. https://munk.org/typecast/2012/08/17/kroy-80-80k-sales-broch...

Post reply on HN