A knowledge base article about Network Printer Security Best Practices provided by the UC Berkeley IT Service Hub - Knowledge Portal
Multifunction printers (MFPs) are really full-fledged networked computers. To secure your printers from unauthorized access, print configuration alterations, eavesdropping, and device compromise follow these printer security best practices:
Take the following appropriate measures to make sure that the printer is configured only to allow access from approved networks and devices:
Do it now! If your printer's administrative panel is not securely configured, attackers can potentially:
An attacker with unauthorized access can also install malware on the printer allowing remote back-door access.
For example, when accessing the printer interface via a web browser, use an "https://" address (which uses SSL encryption) instead of a regular "http://" address. If you need command line access, use SSH instead of Telnet to prevent eavesdropping.
Many printers have insecure and unnecessary protocols enabled by default (e.g., Telnet, HTTP, FTP). Leaving these services enabled provides attackers with the ability to access the printer data directly. While a practical joker with limited knowledge of printer job language (PJL) might only Telnet to change the "Ready" message to something cute ("Insert Coin"), a more malicious attacker could potentially browse the printer's hard drive and view all the data stored there, including sensitive documents to be printed.
Proactively running only necessary services and disabling insecure/unnecessary services prohibits your printer from being used for unintended purposes, such as hosting pornography, or as an FTP server for copyright-protected music and movies.
Just like computers, printers and multi-function devices need updates and patches. Check for firmware updates on all printer and network devices as part of your regular patch management schedule. Updates can add new or improved security features, patch known security holes, and fix other issues.
Keeping your multi-functional printer up to date prevents unintentionally exposing sensitive campus data to unauthorized access and misuse.
Home and small office printers are not well-suited to be connected to UC Berkeley's high speed, open network. These low-cost printers often do not meet the campus basic Minimum Security Standards for Networked Devices (MSSND). If the printer is used to handle sensitive information, a home or small office printer is even less likely to have the security functionality necessary to meet the more stringent MSSND requirements for sensitive data.
For shared departmental printing, select a business workgroup printer. These printers store print jobs, passwords and other information on their hard drives, and provide disk encryption to protect sensitive data stored on the device. They can also erase data after the print job has run.
When a printer is de-provisioned or sent offsite for servicing, make sure to wipe any stored data. Everything printed, copied, faxed, or scanned is stored on the printer hard drive and may be retrieved if not securely deleted.
The UCSF Print Management Program is available to UC Berkeley campus departments as a complete printer/copier management service.
If you notice unwanted printouts (spam, harassment, or offensive material) happening in your department, please contact IT Client Services (email itcshelp@berkeley.edu) as soon as possible to assist in securing your printers and report the security issue to the Information Security Office.