HP launches a bug bounty program for printers

Shawn Knight

Posts: 15,294   +192
Staff member
Why it matters: Having one of its printers facilitate an attack on a company wouldn't be a good look for HP. By investing in preventative measures like a bug bounty program, HP could potentially save face - and money - in the long run.

HP has partnered with bug bounty platform Bugcrowd to launch the industry’s first bug bounty program for printing devices.

Security vulnerabilities are traditionally associated with PCs and networking devices but lately, hackers have been turning their attention to connected devices such as security cameras, smart home devices and printers. Such is true in both consumer and enterprise settings, the latter of which appears to be HP’s primary concern.

Justine Bone, CEO of MedSec and security advisory board member for HP, said CISOs are rarely involved in printing purchase decisions yet play a critical role in the overall health and security of their organization.

Bugs submitted and verified by Bugcrowd will be eligible for awards of up to $10,000 based on the severity of the flaw. Bugs that have previously been discovered by HP will be assessed and in some cases, a reward may be offered as a good faith payment.

Shivaun Albright, HP's chief technologist of printing security solutions, told CNET in a recent interview that the program quietly kicked off in May with 34 researchers. The company has already paid out one award of $10,000, Albright confirmed.

Permalink to story.

 
I must admit that when I read the headline I laughed and laughed. HP lost their mojo in the printer market decades ago. I have a friend in the IT business with them that used to constantly tell me how their meetings were filled with nothing more than where they going drinking next weekend and who was sleeping with whom .... never anything to do with technical problem solving or support to their users. At one time they made the #1 plotter in the world, but now that has fallen by the wayside and their product support .... another burst of laughter. I seriously doubt this latest effort will have any impact, unless they meet to discuss it in a bar while they are swapping partners .....
 
Bug Hunter: Hi. I am writing to you to inform you of a bug I found. In almost every occasion the HP printer informs me of empty cartridges, while they are still full of ink.

HP: Dear Bug Hunter, thank you for contacting us. Unfortunately, what you describe is not a bug, it's a feature.
 
Bug Hunter: Hi. I am writing to you to inform you of a bug I found. In almost every occasion the HP printer informs me of empty cartridges, while they are still full of ink.

HP: Dear Bug Hunter, thank you for contacting us. Unfortunately, what you describe is not a bug, it's a feature.

Bug Hunter: This bug/feature was in the last HP InkJet printer I owned (Over 10 years ago). When the ink gets low the printer would print a re-calibration page to adjust how much inc it put on the paper. This would happen automatically thus wasting ink and my expensive Photo paper. This was the last HP Ink Jet I owned or will ever own.
 
Back