Are you still using the Default Admin password on every copier you install?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • SalesServiceGuy
    Field Supervisor

    Site Contributor
    5,000+ Posts
    • Dec 2009
    • 7874

    Are you still using the Default Admin password on every copier you install?

    I know it is easier to leave the default Admin password on every copier/printer you install the same.

    Copier/Print manufacturers have invested $$$ in making their devices more secure but this can all be easily defeated by Googling common device passwords like "Admin/ 123456".

    Many low end print devices do not even have an Admin password enabled. It is there but requires a little extra effort to enable.

    Are you making life easier for hackers to attack your customer with Ransomware?

    Ransomware attacks are escalating around the world with high $ demanded and potentially crippling consequences.

    No one expects you to rush out and change all of the default passwords in your care but if your client has a 3rd party security audit performed, any default password will be immediately flagged as a risk.

    I know there are lots of free methods to record your new passwords but how would you plan to implement this over 100's of print devices in your care?
    Last edited by SalesServiceGuy; 04-12-2021, 06:59 PM.
  • SalesServiceGuy
    Field Supervisor

    Site Contributor
    5,000+ Posts
    • Dec 2009
    • 7874

    #2
    Re: Are you still using the Default Admin password on every copier you install?

    What effect can changing the default Admin password have on used equipment purchased from a 3rd party equipment broker?

    Comment

    • srvctec
      Former KM Senior Tech

      500+ Posts
      • Oct 2009
      • 827

      #3
      Re: Are you still using the Default Admin password on every copier you install?

      I've been trying to get our customers to change the default admin password for a few years but they don't want to (neither do the other techs). To me it's just common sense to change it but laziness runs deep. I'm finally getting the CE Auth turned on for most of our machines (well, until another tech just turns it off because it's too much trouble for them) because everybody else is too lazy and thinks it's just stupid. We've already had an accounting firm say they were audited and discovered default admin passwords on our equipment a few years ago so they put in their own. I've come up with our own to use on all our customer's machines if they don't want to use their own but like I said, nobody wants to remember a new one, even after being explained to about it being a security risk.
      Started in the copier service business in the fall of 1988 and worked at the same company for 33.5 years, becoming the senior tech in 2004 but left to pursue another career on 4/29/22.

      Comment

      • bsm2
        IT Manager

        25,000+ Posts
        • Feb 2008
        • 27447

        #4
        Re: Are you still using the Default Admin password on every copier you install?

        The problem is on some machines if you forget or change it the only way to reset it is to wipe everything on that equipment.

        Comment

        • tsbservice
          Field tech

          Site Contributor
          5,000+ Posts
          • May 2007
          • 7635

          #5
          Re: Are you still using the Default Admin password on every copier you install?

          Originally posted by srvctec
          I've been trying to get our customers to change the default admin password for a few years but they don't want to (neither do the other techs). To me it's just common sense to change it but laziness runs deep. I'm finally getting the CE Auth turned on for most of our machines (well, until another tech just turns it off because it's too much trouble for them) because everybody else is too lazy and thinks it's just stupid. We've already had an accounting firm say they were audited and discovered default admin passwords on our equipment a few years ago so they put in their own. I've come up with our own to use on all our customer's machines if they don't want to use their own but like I said, nobody wants to remember a new one, even after being explained to about it being a security risk.
          This is very stupid action I mean to turn off CE mode password. What a lazy techs you work with. Without CE password you cannot use Remote panel for example(very useful) plus if you need to repeatedly enter Admin and CE passwords you can use temporarily Maintenance mode.
          But letting/persuading EVERY user change Admin password is huge huge task. I mean I'm all in with that but aftereffects are frightening at least. This must be charged 100% if they forget/lost their own password plus enormous efforts to find someone tells you Admin password(or input it on behalf of you) on every single account. I made remote maintenance on hundreds devices and without Admin password will have no chance to do a simple tasks not even updating the Firmware in background(outside of business hours).
          A tree is known by its fruit, a man by his deeds. A good deed is never lost, he who sows courtesy, reaps friendship, and he who plants kindness gathers love.
          Blessed are they who can laugh at themselves, for they shall never cease to be amused.

          Comment

          • SalesServiceGuy
            Field Supervisor

            Site Contributor
            5,000+ Posts
            • Dec 2009
            • 7874

            #6
            Re: Are you still using the Default Admin password on every copier you install?

            Originally posted by srvctec
            I've been trying to get our customers to change the default admin password for a few years but they don't want to (neither do the other techs). To me it's just common sense to change it but laziness runs deep. I'm finally getting the CE Auth turned on for most of our machines (well, until another tech just turns it off because it's too much trouble for them) because everybody else is too lazy and thinks it's just stupid. We've already had an accounting firm say they were audited and discovered default admin passwords on our equipment a few years ago so they put in their own. I've come up with our own to use on all our customer's machines if they don't want to use their own but like I said, nobody wants to remember a new one, even after being explained to about it being a security risk.
            The abbreviation CE Auth stands for?

            "but laziness runs deep" is the key phrase. Many customers do not understand the risks of malware infecting their network.

            Comment

            • SalesServiceGuy
              Field Supervisor

              Site Contributor
              5,000+ Posts
              • Dec 2009
              • 7874

              #7
              Re: Are you still using the Default Admin password on every copier you install?

              Originally posted by bsm2
              The problem is on some machines if you forget or change it the only way to reset it is to wipe everything on that equipment.
              One way to get around this is to subscribe for a fee to a service like Password Manager for Families, Businesses, Teams | 1Password where every password is recorded behind one password to enter the site.

              Comment

              • SalesServiceGuy
                Field Supervisor

                Site Contributor
                5,000+ Posts
                • Dec 2009
                • 7874

                #8
                Re: Are you still using the Default Admin password on every copier you install?

                If a copier is protected by a default User Name and a password, is it necessary to change both the User Name and the Password or just the password?

                Comment

                • KenB
                  Geek Extraordinaire

                  2,500+ Posts
                  • Dec 2007
                  • 3946

                  #9
                  Re: Are you still using the Default Admin password on every copier you install?

                  Originally posted by SalesServiceGuy
                  The abbreviation CE Auth stands for?

                  "but laziness runs deep" is the key phrase. Many customers do not understand the risks of malware infecting their network.
                  “I think you should treat good friends like a fine wine. That’s why I keep mine locked up in the basement.” - Tim Hawkins

                  Comment

                  • copier tech
                    Field Supervisor

                    5,000+ Posts
                    • Jan 2014
                    • 7931

                    #10
                    Re: Are you still using the Default Admin password on every copier you install?

                    Originally posted by SalesServiceGuy
                    I know it is easier to leave the default Admin password on every copier/printer you install the same.

                    Copier/Print manufacturers have invested $$$ in making their devices more secure but this can all be easily defeated by Googling common device passwords like "Admin/ 123456".

                    Many low end print devices do not even have an Admin password enabled. It is there but requires a little extra effort to enable.

                    Are you making life easier for hackers to attack your customer with Ransomware?

                    Ransomware attacks are escalating around the world with high $ demanded and potentially crippling consequences.

                    No one expects you to rush out and change all of the default passwords in your care but if your client has a 3rd party security audit performed, any default password will be immediately flagged as a risk.

                    I know there are lots of free methods to record your new passwords but how would you plan to implement this over 100's of print devices in your care?
                    Yes leave them as the factory default.

                    If a hacker has managed to gain access to the customers network they wont be interested in the copier, more their server.

                    Let us eat, drink, and be merry, because tomorrow we may die!

                    For all your firmware & service manual needs please visit us at:

                    www.copierfirmware.co.uk - www.printerfirmware.co.uk

                    Comment

                    • BillyCarpenter
                      Field Supervisor

                      Site Contributor
                      VIP Subscriber
                      10,000+ Posts
                      • Aug 2020
                      • 14755

                      #11
                      Re: Are you still using the Default Admin password on every copier you install?

                      Originally posted by copier tech
                      Yes leave them as the factory default.

                      If a hacker has managed to gain access to the customers network they wont be interested in the copier, more their server.

                      I don't have a dog in this race but I think the counter argument would be "what documents are stored on the hard drive of the copier"? Tax returns? Personal info? Hackers like to go for the low hanging fruit.
                      Adversity temporarily visits a strong man but stays with the weak for a lifetime.

                      Comment

                      • BillyCarpenter
                        Field Supervisor

                        Site Contributor
                        VIP Subscriber
                        10,000+ Posts
                        • Aug 2020
                        • 14755

                        #12
                        Re: Are you still using the Default Admin password on every copier you install?

                        Originally posted by SalesServiceGuy

                        I know there are lots of free methods to record your new passwords but how would you plan to implement this over 100's of print devices in your care?

                        Why would you need a different password for each machine if the objective is to keep a hacker from finding the default password on google? Couldn't you change to the password and use the same one for all machines?
                        Adversity temporarily visits a strong man but stays with the weak for a lifetime.

                        Comment

                        • KYO_OEM
                          Senior Tech

                          500+ Posts
                          • Aug 2011
                          • 636

                          #13
                          Re: Are you still using the Default Admin password on every copier you install?

                          @Billy,

                          KDC is not sleeping.
                          California IoT Security Act SB 327 Enclosed new security rule for next generation of Iris (TaskAlfa 2554ci, etc..)If "older" systems get this "modification", i don`t know at the moment.
                          new security settings.JPG

                          Comment

                          • BillyCarpenter
                            Field Supervisor

                            Site Contributor
                            VIP Subscriber
                            10,000+ Posts
                            • Aug 2020
                            • 14755

                            #14
                            Re: Are you still using the Default Admin password on every copier you install?

                            Originally posted by KYO_OEM
                            @Billy,

                            KDC is not sleeping.
                            California IoT Security Act SB 327 Enclosed new security rule for next generation of Iris (TaskAlfa 2554ci, etc..)If "older" systems get this "modification", i don`t know at the moment.
                            [ATTACH=CONFIG]48899[/ATTACH]

                            Thanks KYO. You always provide the correct answer.
                            Adversity temporarily visits a strong man but stays with the weak for a lifetime.

                            Comment

                            • SalesServiceGuy
                              Field Supervisor

                              Site Contributor
                              5,000+ Posts
                              • Dec 2009
                              • 7874

                              #15
                              Re: Are you still using the Default Admin password on every copier you install?

                              Originally posted by BillyCarpenter
                              Why would you need a different password for each machine if the objective is to keep a hacker from finding the default password on google? Couldn't you change to the password and use the same one for all machines?

                              ... that would be a violation of a Security audit. Each network device must have a different password.

                              Comment

                              Working...