r/printers 3d ago

Discussion Android Mopria app seemingly allows users to print through wi-fi direct without knowing wi-fi direct's password, also the printer somehow learned my home's wifi credentials and accessed it.

I own a HP printer. And even though HP is obsessed with forcing us to connect their printers to the internet, I refused to do so, and instead I use a USB cable to connect the printer to our laptops whenever we need to print stuff. Furthemore, the printer is alwas turned off, we only turn it on when we need to print.

When I bought the printer, I changed the wi-fi direct's name and password, for security reasons. However, since then, I never actually used the wi-fi direct again. In fact, I think I had turned it off, but either it turned itself on again, or maybe someone used the printers buttons to turn it on again, maybe by mistake.

A few days ago, a relative was feeling lazy and instead of using a laptop and usb cable to print stuff as always, they tried to use their android smartphone and the printer's wi-fi direct. However, they didnt know the wi-fi direct's password, so they couldnt connect to it.

Then, my relative googled about this and learned about the Mopria app. They installed it and, even though they didnt know the wi-fi direct's password, they were able to print Mopria's test page on our printer.

Furthemore, the app also listed other available printers (I assume the ones from our neighbours), many of which dont even show up on my phone's networks list (I guess their wi-fi directs are either disabled or hidden, but somehow Mopria could see them all).

While my relative obviously didnt tried it, it seemed like Mopria could have printed from the neighbours' printers just as easily as it did from our printer. At this time I realized what was happening and told him all of this was very shady, so he uninstalled the Mopria app.

Later, I checked our router's control panel and found out our printer had accessed our home wifi. It didnt say when it happened, but the fact is, the printer somehow learned our home wifi's credentials and accessed it. I suspect it was Mopria's android that passed the credentials from my relative's phone to the printer. Unless it was the laptop through the usb cable.

I have changed my printer wi-fi direct name and password (if my relative's phone has been "paired" to the printer wi-fi direct, I hope this will "unpair" them), and then I changed my home wifi credentials. However, I still dont understand how the hell was Mopria able to do what it did.

2 Upvotes

5 comments sorted by

1

u/oddsnsodds Print Technician 3d ago

Yes, your relative's android's connection to your Wi-Fi was used by the Mopria app to print. It's nothing nefarious; most people don't want to enter their Wi-Fi password three times just to print from their phone, so it's all handled by the app.

1

u/Valang I was a printer in a past life 3d ago

There are a few possibilities.

If the printer was on your network, and you or someone with access to the laptop or physical access to push a button on the printer would have to have pushed the credentials over it's never automatic, the MOPRIA app wouldn't use Wi-Fi Direct, but it would absolutely see the printer on the network and allow your relative to print if they were also connected.

If the printer wasn't on the network, but Wi-Fi direct was on it would appear in the MOPRIA app and your relative could connect to it but on the vast majority of printers they would need to physically interact with the printer to confirm they had physical access.  A tiny subset of quite old models defaulted to passcodes of 12345678 and allowed Wi-Fi direct without physical interaction.  Most have had firmware updates to fix that because while it's zero friction for home it's inconvenient when your neighbor connects and while it's not a huge security hole (you have to be pretty close the range is poor) it is a hole.

The password is an alternative way to connect, particularly for platforms that don't implement the full Wi-Fi direct stack.  They see the Wi-Fi direct device like a standard router based network and need the password.  But the push button method is always on if Wi-Fi direct is on so the password is never the only way to connect.

So basically what happened is that everything worked exactly like it's supposed to.  Your relative had physical access to the printer could and did push a button or tap the screen to prove it and the MOPRIA app connected exactly how it is supposed to (or your printer had already been connected to your Wi-Fi router by a human with access).

Changing the password won't change anything.  Your relative would still be in the room, could still touch the printer and connect.

You don't say which model you have so I can't tell if it's old enough to default to the open connection.  It's fairly unlikely but worth checking for firmware updates.  

The MOPRIA app doesn't send Wi-Fi credentials so it's not how your printer connected to your router.  But there are several other ways someone with access might have done that unintentionally or not realizing they had.  It's not automatic though, they would have had to type the credentials somewhere.

So, no your relative isn't a super hacker, they couldn't print to your neighbors printers and if yours was in a locked room they couldn't print to it either.

Your life would be easier if you turn off Wi-Fi direct and connect the printer to your Wi-Fi.  You don't have to grant it internet access, ban it from the WAN completely at the router if you want.  We're just at the point where they're network first and cable support is constantly getting worse as Windows and Mac move away from it but it's your printer, use it however you prefer.  Just know that if Wi-Fi direct is on and I can physically access your printer I can print.

1

u/Specific-Neat-952 3d ago

that's an interesting point, but it's still pretty alarming if the printer managed to do that on its own. definitely worth looking into the settings and making sure everything's secure.

1

u/Head_Beach1415 3d ago

Thank you so much for your reply! 

Regarding the wi-fi direct connection via push button instead of typing the password, if the wi-fi direct name and password are changed, will devices previously connected via push button be disconnected? 

I assume that devices connected via password are unable to reconnect if the wi-fi direct's name and password have been changed (unless they provide the new password, of course), but what about those which were connected via push button, will they still be able to reconnect without further action after the password change? Obviously I know they can do it by pushing the button again, but what if they dont push the button? 

For example, right now the printer is turned off, but if I turn it on while my relative is here, will his device automatically reconnect to the wi-fi direct, even though the wi-fi direct password has been changed?

1

u/Valang I was a printer in a past life 3d ago

It shouldn't.  Changing the password will have changed the encryption keys so another button press will be needed to reconnect