Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Hardware Password Defaults – Do You Change Them?

By Sean Lawless on September 12, 2016
Email this postTweet this postLike this postShare this post on LinkedIn

IT professionals have long understood the importance of changing the default password for network connected hardware devices (printers, switches, wireless access points, etc.). In the world of the Internet Of Things it seems everything is connected to the internet, the locks to your house, the refrigerator, your car, the wireless router from the cable company, the list goes on. All of these devices have a default user name and password for managing settings. IT professionals should know better than to ever leave those administrator passwords as default, but does the general public?

In September of 2015, the InfoSec Institute published a detailed article regarding the exploitation of corporate printers (InfoSec Institute).  In January 2016, several news outlets reported on hackers using the storage in network connected printers and multi-function devices to store and execute malicious code (SecurityWeek).  In March, it was reported how hackers printed anti-Semitic flyers to thousands of publicly accessible printers (WashingtonPost). As recently as Friday September 9, Security Week reported on a new malware variant, Mal/Miner-C, discovered by Sophos that specifically targets network attached storage devices, leveraging default user name and passwords (SecurityWeek).

Whether you are an IT professional or a home consumer, hackers continue to exploit vulnerabilities in other network connected devices beside your traditional computer. Based on the recent discovery of Mal/Miner-C, hackers continue to see the default user name and password as a way into those devices. Clearly we are not doing a good enough job at adhering to what amounts to age old advice; change the default administrator password immediately and disable any unused or unnecessary services. If you don’t plan to have your refrigerator order your groceries for you, turn that service off and be sure to change the default password on that fancy new garage door lifter.

Photo of Sean Lawless Sean Lawless

Sean is Robinson+Cole’s Infrastructure & Security Manager, a member of the firm’s Data Privacy + Cybersecurity Team, and a non-attorney contributor to the Data Privacy + Cybersecurity Insider blog. He has spent more than a decade helping professional services organizations in various industries…

Sean is Robinson+Cole’s Infrastructure & Security Manager, a member of the firm’s Data Privacy + Cybersecurity Team, and a non-attorney contributor to the Data Privacy + Cybersecurity Insider blog. He has spent more than a decade helping professional services organizations in various industries, develop and implement practical information security programs based on industry standard frameworks. Sean holds a Bachelor of Science degree from the University of Connecticut and is a member of several cybersecurity professional organizations.

Read more about Sean LawlessEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity, Technology and AI
  • Blog:
    Data Privacy + Cybersecurity Insider
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo