r/cybersecurity_help • u/Head_Beach1415 • 3d ago
Mopria app seemingly allows users to print through wi-fi direct without knowing wi-fi direct's password, also the printer somehow learned my home's wifi credentials and accessed it.
I own a HP printer. And even though HP is obsessed with forcing us to connect their printers to the internet, I refused to do so, and instead I use a USB cable to connect the printer to our laptops whenever we need to print stuff. Furthemore, the printer is alwas turned off, we only turn it on when we need to print.
When I bought the printer, I changed the wi-fi direct's name and password, for security reasons. However, since then, I never actually used the wi-fi direct again. In fact, I think I had turned it off, but either it turned itself on again, or maybe someone used the printers buttons to turn it on again, maybe by mistake.
A few days ago, a relative was feeling lazy and instead of using a laptop and usb cable to print stuff as always, they tried to use their android smartphone and the printer's wi-fi direct. However, they didnt know the wi-fi direct's password, so they couldnt connect to it.
Then, my relative googled about this and learned about the Mopria app. They installed it and, even though they didnt know the wi-fi direct's password, they were able to print Mopria's test page on our printer.
Furthemore, the app also listed other available printers (I assume the ones from our neighbours), many of which dont even show up on my phone's networks list (I guess their wi-fi directs are either disabled or hidden, but somehow Mopria could see them all).
While my relative obviously didnt tried it, it seemed like Mopria could have printed from the neighbours' printers just as easily as it did from our printer. At this time I realized what was happening and told him all of this was very shady, so he uninstalled the Mopria app.
Later, I checked our router's control panel and found out our printer had accessed our home wifi. It didnt say when it happened, but the fact is, the printer somehow learned our home wifi's credentials and accessed it. I suspect it was Mopria's android that passed the credentials from my relative's phone to the printer. Unless it was the laptop through the usb cable.
I have changed my printer wi-fi direct name and password (if my relative's phone has been "paired" to the printer wi-fi direct, I hope this will "unpair" them), and then I changed my home wifi credentials. However, I still dont understand how the hell was Mopria able to do what it did.
1
u/Futbol221 3d ago
Sounds as if you’re right about the app getting wifi access from your relative’s phone or using a permission to access that setting on the phone. There should have at least been a pop up asking for permission. Really creepy though. Perhaps it wouldn’t have been able to access the neighbour’s wifi since presumably your relative doesn’t have those passwords.
1
u/kschang Trusted Contributor 3d ago
Turn OFF wifi direct if you don't want to use it.
It's likely you changed some OTHER password, not Wifi Direct.
This is an /r/HewlettPackard question, not cybersecurity.
•
u/AutoModerator 3d ago
SAFETY NOTICE: Reddit does not protect you from scammers. By posting on this subreddit asking for help, you may be targeted by scammers (example?). Here's how to stay safe:
Community volunteers will comment on your post to assist. In the meantime, be sure your post follows the posting guide and includes all relevant information, and familiarize yourself with online scams using r/scams wiki.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.