Page 3 of 3 FirstFirst 123
Results 21 to 28 of 28
  1. #21
    Service Manager 2,500+ Posts rthonpm's Avatar
    Join Date
    Aug 2007
    Location
    Pennsyltucky
    Posts
    2,792
    Rep Power
    108

    Re: Are you still using the Default Admin password on every copier you install?

    Quote Originally Posted by SalesServiceGuy View Post
    ... a modern security audit would flag using the password DSC328 on 2+ machines as a security weakness.
    Unless you have other compensating controls in place. We just placed several MFP's with a regulated customer, all of them have the same admin credentials but the web interface is only available from a single administrative system that is accessible via AD by specific staff, anyone else who tries to log in is blocked by Group policy.

    Yes, you could use the credentials from the machine's op panel, but at that point you're not getting very far since the machines can only talk to two internal servers, and those are configured using Windows authentication which isn't directly accessible from either the web interface or the machine itself.

    It all depends on how granular you want to get, and even in smaller environments we may set up different admin accounts for different functions.

    Overall, we definitely do NOT use the default passwords on any MFP. We will set one just for our staff for customer machines so that there is a fallback if they forget their password, but only two of our staff have access to those, and if it gets used for a specific machine, we will change it on the next service visit.

  2. #22
    Service Manager 5,000+ Posts tsbservice's Avatar
    Join Date
    May 2007
    Posts
    7,142
    Rep Power
    346

    Re: Are you still using the Default Admin password on every copier you install?

    Quote Originally Posted by SalesServiceGuy View Post
    ... so how did you store and retrieve 100s of unique passwords?

    I am aware of the California law requiring all IOT (Internet of Things) devices to be programmed upon first install away from the default password. I am not aware that this law was enacted anywhere else.
    Nope. Most of techs would turn off any password they can as too much grief. There's no advanced law enforcements here but I like to be proactive. They will come soon or later.
    A tree is known by its fruit, a man by his deeds. A good deed is never lost, he who sows courtesy, reaps friendship, and he who plants kindness gathers love.

    Blessed are they who can laugh at themselves, for they shall never cease to be amused.

    I don't reply to private messages from end users.

  3. #23
    Service Manager 5,000+ Posts
    Are you still using the Default Admin password on every copier you install?

    SalesServiceGuy's Avatar
    Join Date
    Dec 2009
    Location
    Nova Scotia
    Posts
    7,728
    Rep Power
    225

    Re: Are you still using the Default Admin password on every copier you install?

    Quote Originally Posted by BillyCarpenter View Post
    Use the serial number.
    I like this idea. Use the last four-six digits of the copier's serial #. It is always on the copier somewhere but there is no way a hacker could know it unless they are physically near the copier.

  4. #24
    Service Manager 5,000+ Posts
    Are you still using the Default Admin password on every copier you install?

    copier tech's Avatar
    Join Date
    Jan 2014
    Location
    London
    Posts
    7,554
    Rep Power
    182

    Re: Are you still using the Default Admin password on every copier you install?

    Quote Originally Posted by SalesServiceGuy View Post
    I like this idea. Use the last four-six digits of the copier's serial #. It is always on the copier somewhere but there is no way a hacker could know it unless they are physically near the copier.

    On Ricoh for example you can view the serial number BEFORE logging in!

    Not sure about other manufacturers.
    Let us eat, drink, and be merry, because tomorrow we may die!

    For all your firmware & service manual needs please visit us at:

    www.copierfirmware.co.uk - www.printerfirmware.co.uk




  5. #25
    Service Manager 10,000+ Posts
    Are you still using the Default Admin password on every copier you install?

    BillyCarpenter's Avatar
    Join Date
    Aug 2020
    Location
    Long Beach, Mississippi
    Posts
    13,444
    Rep Power
    448

    Re: Are you still using the Default Admin password on every copier you install?

    Full credit goes to KYO for the serial number idea. It was in the attachment that he posted.

  6. #26
    Retired 10,000+ Posts
    Are you still using the Default Admin password on every copier you install?

    slimslob's Avatar
    Join Date
    May 2013
    Location
    Bakersfield, CA
    Posts
    34,229
    Rep Power
    991

    Re: Are you still using the Default Admin password on every copier you install?

    Quote Originally Posted by KYO_OEM View Post
    @Billy,

    KDC is not sleeping.
    California IoT Security Act SB 327 Enclosed new security rule for next generation of Iris (TaskAlfa 2554ci, etc..)If "older" systems get this "modification", i don`t know at the moment.
    Attachment 48899
    If that were the case then every Windows 10 computer sold in California is in violation.

  7. #27
    Retired 10,000+ Posts
    Are you still using the Default Admin password on every copier you install?

    slimslob's Avatar
    Join Date
    May 2013
    Location
    Bakersfield, CA
    Posts
    34,229
    Rep Power
    991

    Re: Are you still using the Default Admin password on every copier you install?

    This entire discussion is moot at least for Ricoh. With as many people that have openly posted certain proprietary information here, any hacker in the world would have ne problem resetting the passwords to default.

  8. #28
    Service Manager 5,000+ Posts
    Are you still using the Default Admin password on every copier you install?

    SalesServiceGuy's Avatar
    Join Date
    Dec 2009
    Location
    Nova Scotia
    Posts
    7,728
    Rep Power
    225

    Re: Are you still using the Default Admin password on every copier you install?

    Quote Originally Posted by copier tech View Post
    On Ricoh for example you can view the serial number BEFORE logging in!

    Not sure about other manufacturers.
    Not on a Toshiba but excellent point! This assumes that a hacker knows the IP address of the copier.

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Get the Android App
click or scan for the Copytechnet Mobile App

-= -= -= -= -=


IDrive Remote Backup

Lunarpages Internet Solutions

Advertise on Copytechnet

Your Link Here