Skip to main content

Canon mulls security concerns after hacker gets Doom running on a Pixma printer

hacker gets doom running canon printer
Image used with permission by copyright holder
White hat security researcher Michael Jordon has managed to get id Software’s genre-defining first-person shooter Doom running on a wireless Canon Pixma printer.  The project, which took four months to get up and running, was undertaken to demonstrate a security vulnerability in the printer’s web interface that is exemplary of problems that could potentially plague the emerging “Internet of Things” (via BBC News).

The Canon Pixma uses a Web interface so that owners can check on its status remotely. Mr. Jordon found that the interface does not require a username or password, so anyone could check on the device’s status once they found it. This did not seem like a problem until he realized that it is also possible to update the device’s firmware through the remote Web interface. Although the firmware is encrypted, Mr. Jordon was able to crack it and thus convince the printer to accept his own, re-written firmware.

That’s when he got the idea to run Doom, which has become a de facto “Hello, World!” program for hackers to demonstrate mastery over a given device. Doom has been implemented on everything from ATMs to graphic calculators. “Running Doom, that’s real proof you control the thing,” Jordon told the BBC.

Related: The return of Doom will be teased in an upcoming beta

Although the printer’s 32-bit ARM processor and 10MB of memory was more than sufficient in terms of raw power, the lack of a conventional operating system meant that it took months of coding and experimentation so the game could deal with the printer’s idiosyncrasies. The color palette is off, but the game works sufficiently to prove Mr. Jordon’s point, and he has no plans to further optimize it.

In response to Mr. Jordon’s work, Canon has promised “to provide a fix as quickly as is feasible,” adding a username and password to all future Pixma printers and providing an update for all models launched from the second half of 2013 onward. A quick search on the Shodan search engine reveals that there are thousands of unsecured printers out there on the Web, though Mr. Jordon has found no evidence of anyone abusing the loophole.

For a more technically in-depth explanation of how Jordon hacked the printers’s encryption, check out his blog post over at the site of his employer, Context Information Security.

Will Fulton
Former Digital Trends Contributor
Will Fulton is a New York-based writer and theater-maker. In 2011 he co-founded mythic theater company AntiMatter Collective…
This Lenovo gaming PC with RTX 3050 and 16GB of RAM is on sale for $650
The Lenovo LOQ Tower Gaming Desktop on a white background.

You don't have to spend more than $1,000 for a powerful gaming PC because there are budget-friendly options like the Lenovo LOQ Tower gaming desktop, which is currently even cheaper from Best Buy due to a $250 discount. From an already affordable sticker price of $900, the machine is down to just $650 -- but we don't think this price is going to last long. There's a chance that the offer expires as soon as tomorrow, so if you don't want to miss out on the savings, it's highly recommended that you complete your purchase within the day.

Why you should buy the Lenovo LOQ Tower gaming desktop
The Lenovo LOQ Tower is much more affordable than the top-of-the-line models of the best gaming PCs, However, it won't make you feel that you're playing on a budget machine because it's pretty fast and smooth with the 13th-generation Intel Core i5 processor and the Nvidia GeForce RTX 3050 graphics card, plus 16GB of RAM that our guide on how to buy a gaming desktop says will be enough for most gamers. The Lenovo LOQ Tower also comes with a 512GB SSD, for ample storage space for several AAA titles, and with Windows 11 Home pre-loaded, you can start installing the best PC games right after setting it up with its peripherals and power supply.

Read more
Fallout 5: release date speculation, rumors, and news
Two vault-dwellers and a helmet from a set of power armor.

Fallout 5 hasn't officially been announced yet but, with renewed interest in the postapocalyptic series thanks to the new Amazon-produced Fallout TV show, we're starting to hear more and more rumors about the new Wasteland adventure.

Where will the next game take place? What sort of factions will reign supreme in the region this time? And, most importantly, what is the name of the next dog companion?

Read more
You don’t want to miss PS Plus’ great free game lineup this May
Jack holds a sword in Ghostrunner 2 key art.

A new month is upon us, so another batch of PlayStation Plus Essential's monthly free titles is nearly upon us. On May 7, four games will be available for no additional cost to PS Plus Essential subscribers: EA Sports FC 24, Ghostrunner 2, Tunic, and Destiny 2: Lightfall.

EA Sports FC 24 is the latest soccer game to come from the EA Sports brand. Historically, this series was known as FIFA, but EA had to rebrand it after its partnership with that organization ended. Despite that, EA Sports FC 24 is still very much an iteration of FIFA 23, so if you enjoy soccer games and don't already own EA Sports FC 24, it's worth a download. Next is Ghostrunner II, a thrilling first-person action game that launched last October. It's the kind of game that makes you feel like a badass as you precisely platform and strike enemies before they can kill you in one hit.

Read more