Live data from Hacker News

Google has indexed thousands of publicly accessible HP printers

port3000.co.uk

131–140 of 149 posts

Re: Google has indexed thousands of publicly accessible HP printers

#131
post #71

Earlier quoted context omitted.

Why would anyone go to jail for this?

The nail that sticks up gets hammered. If someone else later does something bad with the publicly accessible printer and there's a witch hunt for the responsible party, and the only lead they have is that you emailed them about the possibility in advance...then they'll go after you, even though you were just trying to do a good thing. And if you're expecting the victim / police / legal system to understand that, tech…

Ok, but IP logs would throw down their assumptions. They wouldn't be able to prove a thing.

Re: Google has indexed thousands of publicly accessible HP printers

#132
post #71

Earlier quoted context omitted.

Why would anyone go to jail for this?

The nail that sticks up gets hammered. If someone else later does something bad with the publicly accessible printer and there's a witch hunt for the responsible party, and the only lead they have is that you emailed them about the possibility in advance...then they'll go after you, even though you were just trying to do a good thing. And if you're expecting the victim / police / legal system to understand that, tech…

Also, if someone really wanted to do something bad at least they would do it from Tor or a shadowy proxy from eastern Europe...

Re: Google has indexed thousands of publicly accessible HP printers

#133

Earlier quoted context omitted.

Yeah - this was in 1997...

I think that law dates back decades. I don't think it applies to non USPS carriers though. That said my Google-fu is weak against this particular law.

It's not a postal thing, I believe it's common law. If someone ships you something unsolicited, you are under no obligation to return the item or make payment.

Re: Google has indexed thousands of publicly accessible HP printers

#135

Some of the IPs are registered to large US universities, who list abuse/tech support email addresses in their records. I've already emailed several with a headsup and had a couple of "thank you!"s in reply.

You're lucky you haven't gotten accused of "hacking" yet.

Smart good Samaritans still use dead drop email addresses.

Re: Google has indexed thousands of publicly accessible HP printers

#137
post #79

Earlier quoted context omitted.

The same goes for smart tvs. Most of them you can push stuff to via dnla without a password. Much amusement to be had.

I think the Sony TV's offer an onscreen pop-up before accepting commands from unregistered DLNA controllers although maybe that can be faked (and maybe there is a flaw, I've never explored it deeply).

Mine doesn't. Bravia EX series.

Re: Google has indexed thousands of publicly accessible HP printers

#138
post #77

So within 24 hours, lots of people are going to find out what a goatse is I reckon. Even better, a lot of people in the UK have Thomson routers which have an easily calculable WPA default password. Most of these also have smart tvs these days too which will allow anything to be pushed to them.

> Even better, a lot of people in the UK have Thomson routers which have an easily calculable WPA default password. // That rather looks to oversteps the legal line.

Probably yes, but there is no excuse for incompetence on the part of the ISPs when they ship routers to the customers.

Re: Google has indexed thousands of publicly accessible HP printers

#139
post #13

I've written about this before.[1] Many network-connected printers simply assume that the local network they connect to will be securely protected from external threats, so they're not configured to withstand even the simplest of attacks. This is exactly the opposite of what many security experts recommend: devices should be secure regardless of whether the network they're on is secure or not. Bruce Schneier's person…

IMO Bruce Schneider should be more careful because lots of routers are very capable general-purpose computers and he's definitely responsible for what goes out of his IP address.

Just because his WiFi is open doesn't necessarily mean that you'll be able to access his router configuration. And as he says, having an open network means that you have an excuse if someone does use your internet for something illegal...

And it's Schneier.

Re: Google has indexed thousands of publicly accessible HP printers

#140

Earlier quoted context omitted.

Who says I am not authorised? I can claim that public access is an implicit authorization, like any website! And there is no warning or message in the public control panels.

If I leave my keys in the car, leave the car turned on with the door opened, are you authorized to drive my car?

One cannot reason about computers using analogies and expect to come to any useful conclusion.
Post reply on HN