solution Contentsolution Content

SUPPORT COMMUNICATION- CUSTOMER NOTICE

Document ID: c02164443

Version: 1

HP LaserJet Products - Hard Disk Data Security for HP LaserJet Printing Devices

Notice: The information in this document, including products and software versions, is current as of the release date.The information in this document is subject to change without notice.

Release date : 10-May-2010

Last updated : 10-May-2010

Potential Security Impact:
Digital copier hard drives have been reported to retain “an image of every document copied, scanned, or emailed by the machine”, which can be later retrieved.
HP LaserJet Multifunction printers and some models of HP LaserJet printers contain a hard disk drive (HDD). The details section describes how data is managed on printing device HDDs.

Source:HP, HP Product Security Response Team (PSRT)

Details
Document Image Interaction with the Hard Disk
The HP printing device hard disk is involved in document processing in the following ways:
  • Standard print and copy jobs print directly without storing information on the HDD. Advanced output options can use the HDD for temporary files.
  • E-mail, Fax and Network folder scan jobs use the HDD for temporary files. These files are deleted as part of processing the job and are never retained permanently on the HDD.
  • There is no feature or setting to retain standard print and scan jobs permanently on the HDD, with the exception of Stored Faxes, which temporarily store incoming faxes until released with a Fax PIN.
User Initiated Stored Documents
Documents can be stored on the device hard disk intentionally by customers when using the “Stored Jobs” feature. The system can be configured to automatically delete these jobs at 1 hour, 4 hour, 1 day, or 1 week intervals. These jobs include:
  • Stored Jobs
  • Personal Jobs
  • Quick Copy Jobs
  • Proof & Hold Jobs
HP Secure Data Erase Technology
The Secure File Erase feature ensures any hard disk information from print, copy, fax, and scan jobs is securely removed. This capability is provided as a standard feature on HP LaserJet MFPs and printers.
When this data is deleted, the hard disk areas containing the information are filled with random data using either a 1 pass or 3 pass overwrite, ensuring that the information cannot be recovered using diagnostic tools.
This overwrite technology is compliant with the US Government standard defined in NIST SP 800-88.
Protecting Data at Rest
When customer information is present on the hard disk, either as temporary job files or user created Stored Jobs, this is referred to as “Data at rest”. This data can be protected using encryption or authentication such as a job PIN.
The HP Secure Hard Disk solution protects “data at rest” using encryption. All data written to the HP Secure Hard Disk is encrypted using the AES 128 encryption standard. If the hard disk is removed from the system, the encrypted information on the disk is not readable.
Stored and Personal jobs can be configured with a PIN by the user to protect others from printing them at the printing device control panel.
Customer Available Disk Sanitization Features
All information on an HP printing device hard disk can be securely deleted by the customer before disposal, redeployment or end of lease return.
The HP Secure Storage Erase feature overwrites the entire hard disk using HP Secure Data Erase technology (detailed above) with either a 1 pass or 3 pass overwrite. Performing Secure Storage Erase ensures all customer data is securely erased.
When using the HP Secure Hard Disk solution, all data present on the disk can be deleted by using “Secure Hard Disk Erase/Unlock”, which performs a cryptographic erase. This feature of encrypted storage devices renders all data permanently unreadable by resetting the internal encryption keys.
For failed hard disk devices, HP offers a “Defective Media Retention” Carepack. This service allows customers to maintain possession of failed disk storage devices while adjuring to terms and conditions of standard warranty agreements. See www.hp.com/go/carepack for more information.
Customer Data Sanitization by HP
HP understands customer hard disks may contain sensitive business or technological information and employs appropriate security measures using standard industrial practices to safeguard that information.
For hard disks returned to HP refurbish or recycle facilities, the follow procedures are followed.
  • Functional hard disks are wiped with a destructive data pattern to all addressable locations.
  • Non-functional drives are recycled by crushing at a metal separation plant.
note:
Customers with regulatory or government requirements for data confidentiality are encouraged to maintain custody of the storage device or execute the onboard printing device’s data sanitization procedures before releasing the device.
Summary
HP is committed to continually monitoring security issues to insure that our products are as secure as possible. We recommend that you visit hp.com for your particular printer model and visit our secure printing website ( www.hp.com/go/secureprinting) for other important security information.
Components affected:
Hard Drive
Third party products affected : N/A
System management and security procedures must be reviewed frequently to maintain system integrity. HP is continually reviewing and enhancing the security features of software products to provide customers with current secure solutions.

"HP is broadly distributing this Security Bulletin in order to bring to the attention of users of the affected HP products the important security information contained in this Bulletin. HP recommends that all users determine the applicability of this information to their individual situations and take appropriate action. HP does not warrant that this information is necessarily accurate or complete for all user situations and, consequently, HP will not be responsible for any damages resulting from user's use or disregard of the information provided in this Bulletin. To the extent permitted by law, HP disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose, title and non-infringement."
REVISION HISTORY : 1.0

Hardware platforms affected : HP CM8050 Color Multifunction Printer with Edgeline Technology, HP CM8060 Color Multifunction Printer with Edgeline Technology, HP Color LaserJet 4700 Printer series, HP Color LaserJet 4730 Multifunction Printer series, HP Color LaserJet 5550 Printer series, HP Color LaserJet 9500 Multifunction Printer series, HP Color LaserJet CM3530 Multifunction Printer series, HP Color LaserJet CM4730 Multifunction Printer series, HP Color LaserJet CM6030/CM6040 Multifunction Printer series, HP Color LaserJet CP3505 Printer series, HP Color LaserJet CP3520 Printer Series, HP Color LaserJet CP6015 Printer series, HP Color LaserJet Enterprise CM4540 MFP series, HP Color LaserJet Enterprise CP4025 Printer series, HP Color LaserJet Enterprise CP4525 Printer series, HP Color LaserJet Enterprise CP5525 Printer series, HP LaserJet 4100 Multifunction Printer series, HP LaserJet 4240 Printer, HP LaserJet 4250 Printer series, HP LaserJet 4345 Multifunction Printer series, HP LaserJet 4350 Printer series, HP LaserJet 5200 Printer series, HP LaserJet 9000 Multifunction Printer series, HP LaserJet 9040 Printer series, HP LaserJet 9040/9050 Multifunction Printer series, HP LaserJet 9050 Printer series, HP LaserJet Enterprise 500 MFP M525f, HP LaserJet Enterprise 500 color MFP M575dn, HP LaserJet Enterprise 500 color MFP M575f, HP LaserJet Enterprise 600 Printer M603xh, HP LaserJet Enterprise M4555 MFP series, HP LaserJet Enterprise P3015 Printer series, HP LaserJet M3027 Multifunction Printer series, HP LaserJet M3035 Multifunction Printer series, HP LaserJet M4345 Multifunction Printer series, HP LaserJet M5025 Multifunction Printer series, HP LaserJet M5035 Multifunction Printer series, HP LaserJet M9040/M9050 Multifunction Printer series, HP LaserJet P3005 Printer series, HP LaserJet P4014 Printer series, HP LaserJet P4015 Printer series, HP LaserJet P4510 Printer series

Operating systems affected : Not applicable

Software affected : Not applicable

Support Communication Cross Reference ID : IA02164443

HP Inc. shall not be liable for technical or editorial errors or omissions contained herein. The information provided is provided "as is" without warranty of any kind. To the extent permitted by law, neither HP or its affiliates, subcontractors or suppliers will be liable for incidental, special or consequential damages including downtime cost; lost profits; damages relating to the procurement of substitute products or services; or damages for loss of data, or software restoration. The information in this document is subject to change without notice. HP Inc. and the names of HP products referenced herein are trademarks of HP Inc. in the United States and other countries. Other product and company names mentioned herein may be trademarks of their respective owners.