TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Digital Photocopiers Loaded with Secrets (2010)

166 点作者 artsandsci大约 7 年前

11 条评论

kakwa_大约 7 年前
I&#x27;ve seem a similar mistake nearly been made.<p>There was a printer (the big, one cubic meter, enterprise type) in a sensitive air-gaped network that was not used anymore, and there was a plan to reuse it on the main network.<p>It was nearly installed when I saw it and mentioned that these things have hard drives in them to my Security Officer over a coffee.<p>It was promptly removed after that.<p>This organization was quite conscientious about this kind of stuff, every disks was labeled, regularly inventoried and crushed in presence of the Security Officer when not used anymore.<p>But these printers can easily be mismanaged as people don&#x27;t realize they are basically computers that see tons of information.
评论 #17046096 未加载
btown大约 7 年前
&gt; from Affinity Health Plan, a New York insurance company, ... we obtained the most disturbing documents: 300 pages of individual medical records. They included everything from drug prescriptions, to blood test results, to a cancer diagnosis. A potentially serious breach of federal privacy law.<p>&gt; As for Affinity Health Plan, they issued a statement that said, in part, &quot;we are taking the necessary steps to ensure that none of our customers&#x27; personal information remains on other previously leased copiers, and that no personal information will be released inadvertently in the future.&quot;<p>For comparison, per <a href="https:&#x2F;&#x2F;ocrportal.hhs.gov&#x2F;ocr&#x2F;breach&#x2F;breach_report.jsf" rel="nofollow">https:&#x2F;&#x2F;ocrportal.hhs.gov&#x2F;ocr&#x2F;breach&#x2F;breach_report.jsf</a> - &quot;As required by section 13402(e)(4) of the HITECH Act, the Secretary must post a list of breaches of unsecured protected health information affecting 500 or more individuals.&quot;<p>Of course, any single breach of a copier would be limited to the individuals whose documents touched that copier, and might come under this threshold. Affinity is not on the list at the moment - this may be because the news only just broke.<p>But do the regulatory bodies say &quot;Affinity, you were found to not have a procedure for properly disposing of copiers, so we need to assume that you&#x27;ve leaked health information from EVERY disposed copier historically?&quot; Only then would it be treated with the same seriousness that e.g. HIPAA-compliant SaaS services are expected to treat security. Just because copier hard drives aren&#x27;t networked software doesn&#x27;t mean that they don&#x27;t have network-scale security problems.
评论 #17044871 未加载
评论 #17043072 未加载
atVelocet大约 7 年前
&quot;One of the copiers had documents still on the copier glass, from the Buffalo, N.Y., Police Sex Crimes Division.&quot;<p>No comment.
vasili111大约 7 年前
What about personal (home versions) Photocopiers, Scanners and Printers? Did they store similar information too?
评论 #17044352 未加载
评论 #17044037 未加载
NegativeLatency大约 7 年前
&gt; One product from Sharp automatically erases an image from the hard drive. It costs $500.<p>Storing the images isn&#x27;t a bug, it&#x27;s a feature.
dsfyu404ed大约 7 年前
This has been known for a long time now. Articles like this pop up from time to time. Competent IT departments pull hard drives before copiers are gotten rid of.
评论 #17042845 未加载
评论 #17044196 未加载
评论 #17044392 未加载
mathieubordere大约 7 年前
Why do they store everything?
评论 #17042997 未加载
评论 #17043093 未加载
评论 #17042850 未加载
评论 #17042889 未加载
评论 #17043288 未加载
liveoneggs大约 7 年前
fax machines used to leave copies of everything on the roll&#x2F;ribbon&#x2F;drum&#x2F;whatever too. Especially the ones in sealed plastic were often just a giant roll of carbon paper with everything you&#x27;ve ever sent&#x2F;received on it.
评论 #17043404 未加载
metaphor大约 7 年前
Worth noting that NIST has published a brief report[1] providing risk management guidance on this security concern.<p>[1] <a href="http:&#x2F;&#x2F;dx.doi.org&#x2F;10.6028&#x2F;NIST.IR.8023" rel="nofollow">http:&#x2F;&#x2F;dx.doi.org&#x2F;10.6028&#x2F;NIST.IR.8023</a>
syshum大约 7 年前
Given this is from 2010 perhaps people should look at current practices before freaking out.<p>Almost all modern copiers employ some kind of Disk Encryption so this issue has largely been resolved.<p><a href="http:&#x2F;&#x2F;siica.sharpusa.com&#x2F;Document-Systems&#x2F;Security" rel="nofollow">http:&#x2F;&#x2F;siica.sharpusa.com&#x2F;Document-Systems&#x2F;Security</a>
yaccz大约 7 年前
Its from 2010