Brian.oco 0 Posting Whiz

Maybe the guy on those Biz Hubs commercials is right.

Those nefarious multi-function business machines just might be out to get us.

That's the position taken by a North Carolina compuer science professor who says those all-in-one multifunction business machines – the ones that print/ fax/ scan/ and copy -- could be a big security threat for terrorists plotting against the West.

Says Dr. Elva Jones, a Winston-Salem State University professor and chair of WSSU’s computer science department, many of today's digital copiers actually have their own hard drives that store all of the information that's printed, scanned, copied or faxed. If that information gets into the wrong hands, the result could be detrimental to a business.

"I am not aware of any scandalous situations yet of any great magnitude," says Jones, noting that without awareness it’s a matter of time before a controversy arises. "But typically we don't become alert to possible problems until something happens."

He notes that businesses print, scan, copy or fax client-sensitive information (or its own sensitive internal information), all the time without much thought about security risks. However, if the information is saved to a copier's hard drive, the consequences could be huge.

“Imagine the information handled by law firms, banks, accountants, hospitals and research and development firms,” says Jones.

Hard drives are used in printer/copier/fax/scanner machines because they can add to the efficiency of office operations by increasing the speed and traffic on the company's network. In times of heavy traffic, jobs can go to the machine, get stored on the hard drive and processed at a later time, instead of overloading the network.

As popularity and sales of multifunction print/ fax/ scan/ copy machines like Biz Hub increase in business, so should the awareness of the potential security risks, Jones adds.

Jones could be exaggerating the issue. But maybe not. One thing is for sure. The Information Age and the War on Terror appear to be melding a little too quickly for my blood.

Dani AI

Generated

A practical addendum to : treat networked multifunction devices the same way an organization treats any other data-bearing endpoint. They belong in the asset inventory, the risk assessment, and the incident-response plan — not just on the office floor.

Recommended controls and checks:

  • Inventory every printer/MFD and record model, firmware, management IP, and lease/vendor status.
  • Consult vendor documentation for “secure erase”, full-disk encryption, and job-retention settings; enable overwrite or crypto-erase where supported.
  • Turn on authenticated print-release (pull-print) so jobs are not held for anonymous pickup.
  • Limit management interfaces to an admin VLAN and firewall ACLs; disable unused services (Telnet/FTP/anonymous SMB).
  • Route scan-to locations through authenticated shares or secure mail gateways and restrict scan-to destinations with whitelists.
  • Require firmware updates and log device events to central logging/SIEM for review.
  • Periodically verify sanitization: simple “delete” is not enough — obtain proof of overwrite or a third-party verification when sanitizing drives.

Policy and disposal practices:

  • Treat leased returns and trade-ins like hardware disposal: require a certificate of secure data destruction in the contract and verify vendor processes.
  • For highly sensitive data, consider physical removal or destruction of media before leaving custody.
  • Include MFDs in compliance audits (PCI, HIPAA, etc.) and in staff training about what should not be printed/scanned.

Caution: older models and some vendor claims vary — assume persistence until proven otherwise. Adding these practical, documented steps turns the theoretical worry raised in the thread into manageable operational risk.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.