The End of the Print Driver
The printer is the most overlooked endpoint in the enterprise — sitting on the network with system-level privileges, untouched architecturally for 20 years, and quietly perfect for spoofing, DDoS staging, and zombie-printer pivots. Kevin Pickhardt, Executive Chairman of Pharos and a Xerox PARC alum from the era of mice and GUIs, joins Alan Shimel on Techstrong TV to explain why print finally has the security industry’s attention. Kevin walks Alan through Pharos’s founding belief that “devices don’t print, users do,” the company’s invention of pull printing, and the larger shift from securing pages to securing document flows, identities, and Zero-Trust policies across enterprise print. They dig into Microsoft’s Windows Protected Print mandate that deprecates third-party drivers in favor of IPP, why every enterprise needs a migration plan now, and how AI changes the print analytics game once the platform is API-first.
Transcript
Hey everyone, welcome back here to Techstrong TV. I'm happy to introduce you to Kevin Pickard. He's our next guest.
Kevin is the executive chairman at Pharos. That's P-H-A-R-O-S. Kevin, welcome to Techstrong TV.
It's great to have you on here. Thanks, Alan. Appreciate the opportunity to be with you.
My pleasure. Hey, Kevin, we're going to talk about Pharos. We're going to talk about security risks inherent with print infrastructure.
It's something from when I was doing security was a problem. But let's first start with you, Kevin. We don't have a lot of executive chairmans.
We get a lot of CEOs who are also happen to be chairman of the board, but executive chairmans, talk to us. Sure. Well, I've been executive chairman for the last, I guess two and a half years, but prior to that, I was the CEO for 23.
So that's how I started with Pharos Systems, which is a company that was originally started in Auckland, New Zealand, of all places. Mm-hmm. I joined with them post-founding.
Started my career at Xerox, back when Xerox Palo Alto Research Center was doing a lot of the state-of-the-art development in computer science and- Windows and mouses, mice and so forth ... mouse and the windows, the wide area networks. And so I was a computer guy by education and ended up at Xerox.
And then by hook or crook, I ended up leaving Xerox, joining up with this team from Auckland, New Zealand at Pharos Systems, building software around controlling printing, because that was one of those areas that didn't exist back then. And this group in New Zealand had a different approach. " Users make the decisions to print.
They control the printing process. So Pharos, over the years, has done a lot of innovation in building infrastructure and tools for managing print, really with the premise that users print. Devices don't print.
Devices are the endpoint, but it's really about users. And as the industry has shifted more and more to identity and how do we manage users and serve users, Pharos has benefited from that shift and participated in it in our print space. I love it.
I think back to my career and my life. It's a mystery to me how Xerox never dominated the... Yeah.
Well, there was a book written at the time called "Fumbling the Future," which is not exactly how you want your company to be defined. To be known as, but it's not far from the truth either. No, it's not.
I think what people don't necessarily know about Xerox at the time was the patents for all the copiers. At the same time that they're developing the future for computing, the patents on all the copiers that they had created were coming to an end, and Japan manufacturing was going after- That was Japan Inc, right? Oh, yeah.
They were going after the core elements of the Xerox business. And Xerox found itself where the Japan Inc, the Canons and the- OG and all the rest ... Tobas and Konica Minolta, they were selling copiers at the price at which Xerox was manufacturing them.
And that's a go-out-of-business strategy pretty quick. Yeah. So Xerox really had to refocus on its core as a survival decision.
So there's reasons why Xerox was not able to take advantage or full advantage of a lot of the great research they had done at the time, but it is a shame for- Yeah ... people who were there. Yeah.
Crazy times. But- It was ... back to the printing thing.
Look, I remember the difference between, let's say, an office printer as we used to call them, right? Yeah. And your own personal printers.
And there was a long time in my career where I had a personal printer, usually an inkjet. Yeah. With the old, I forget if it was the serial or parallel port now, but the old direct line port right in, and then over the network was the big laser printer that was off somewhere.
The monster that when I had to print something out, multiple pages and all that. But then when I got into security, Kevin, it's when I first became aware that printers equaled attack surface to a certain extent, right? Yeah.
And now you started looking at those things as not just benign helpers, but as entryways for the bad guys- Yeah ... to get in here. Yeah.
And really, it's the printer itself. You've got a physical endpoint, which is getting smarter and smarter and more and more connected through the enterprise. But it even goes back to what you were talking about before around when you look at how printing and the process was designed.
It was designed as a bidirectional communication going on in the development of print drivers. In order to make printing work across all the different platforms and all the different software packages that were creating documents, these print drivers got a very privileged position inside of the operating system. They were designed to run it at the system level.
They were designed with system-level privileges to communicate back and forth across the network. And the crazy thing is, they still are, right? Go back 20 years, today's print infrastructure has changed little in that timeframe.
So it's the printers themselves that are a risk profile, and then it's the printing infrastructure and the nature of this legacy-trusted relationship that printing operates under that creates a very viable attack surface. So yeah, there's a lot of focus on that that a lot of people in security don't think about because printers have been around for so long. We think of it as- Right ...
just not a problem, right? They're in the woodwork, right? Absolutely.
So let's focus specifically into Pharos, though, and what Pharos does to help here. Sure. Well, I mentioned at the start that Pharos originally started with the premise of how do I control printing?
And it started in the university space. So what people probably are familiar with, many if they're working in enterprises and organizations, is this concept of pull printing. It's not I hit File, Print, and the document shows up in the tray.
I hit File, Print, and then the document is held until I authenticate at the printer so that the printer can make sure that the document that I printed is going to end up in only my hands. And that was technology that was designed by Pharos. Really?
So over time, we've built this model of how do I secure documents? Then it became how do I secure document flow? Then it became how do I secure user access and policy?
Are you allowed to print these documents? Is an intern allowed to print HR documents? And then in the last really 10 years for us, we've been redesigning that, too.
This whole thing's, and infrastructure's, moving to the cloud, so it's now how do we build cloud platforms that can manage and handle all of this infrastructure securely? How printers get connected, how users are identified, the flow between them, and how do I do something that printing is not designed for? It's not designed for the cloud, for cloud native, and it's not designed for zero trust security.
So Pharos has really been a company that's focused on how do we build infrastructure that bridges this legacy world of printers and printing and today's world of zero trust identity, endpoint isolation, and so forth. And that's where we spend our time, and we do that largely for enterprises, healthcare, large-scale financial institutions- Sure ... manufacturing and so forth.
We see ourselves as solving those infrastructure problems associated with print. Got it. I just got to ask, AI rearing its head here yet, or any issues around that?
Absolutely is. Well, and we were talking just before coming on air about the conference you were at this week, and Platform Con, and some of your observations about the changing nature of how AI is operating, and really redefining how we think about platforms. And that's true for print, too, right?
Printing infrastructure is a platform. So when we think of the Pharos Print Cloud as a platform, we really need to open it up for APIs and data analytics and how applications are being written for information flowing through this print world. So yeah, even when we go back to technologies that have been around for, depending on the date, arguably print's been around for 580 years, it's still being impacted by this nature of AI.
It's like- I think it was more secure back then, though. I got to tell you the truth, right? It was.
It was. The documents and who had access to documents was probably more secure than it is now, because they moved quickly. Yes.
And with AI, we are seeing that. And there was this whole period of time where we're taking over printers, and zombying them for DDoS kind of attacks, and spoofing, and so forth, and they were the original IoT at some point, when you think about it, right? Right.
And so there's listening or watching, and some things just don't change with that. Kevin, for people who want to check out what Pharos is up to, and especially our enterprise customers out here who deal with this, what's the website? com.
The Pharos was one of the seven ancient wonders of the world. It was a lighthouse at Alexandria, so- That's right ... that's the namesake.
So if you're looking it up- Supposedly it fell into the sea or something, didn't it? Yeah, it was lighting the way for many, many years, and then, yes, as things do, it got toppled. Well, yeah.
There's enough going on in the world, then one more thing to think about. Do you ever think we'll see a point where printing doesn't, that we get our arms around, we do it right? Printing doesn't represent a potential security risk.
All of our printers print easier Right. We've all had that kind of argh, cursing moment because the printer didn't work correctly and- Yeah ... couldn't connect, or something was going on.
Yeah. One of the biggest frustrations in this print space is that software and drivers and firmware has always been so tightly coupled with hardware, that people come out with a new printer family, they come out with a new driver, and that's a new part- Yeah ... of an attack surface.
Right? Yep. And all of these drivers are operating in different operating systems, and you've got hundreds of them that you're managing, and it's just this proliferation.
It's changing. And probably the biggest place that it's changing is Microsoft has announced something called Windows Protected Print. Uh-huh.
Microsoft is re-architecting how print works in its operating system. Fundamentally, because they identified that print was a key source of- Risk ... vulnerability based on its- Yeah ...
architecture. So, they have re-architected how print works, and they are going through that process of shifting all of their operating system to redesigning print and isolating all the third-party drivers and components. So, it's going to be a transition that can't be ignored in the next 18 to 24 months.
I got to tell you, though. Talking about. We were just talking on Techstrong Gang earlier, they just announced they're extending Windows 10 support another year.
Yeah. And maybe more after that. Because the migration from Windows 10 to 11 has been much slower, much less than we've seen in previous versions of Windows.
And if this is going to take Windows 11 or whatever's next, that's the problem here, is a huge chunk of the market is still on 10. Yeah. Well, and Microsoft has already introduced it.
So, this Windows Protected Print- Okay ... new way of delivering printing, is based on standards. It's based on the Internet Printing Protocol, IPP.
Okay. It's a standard that has been out there that is more secure. It's available in Windows today.
It's just that a lot of organizations are choosing not to adopt it yet, because when they do, all of their existing manufacturers' print drivers are going to be obsolete. Have to be thrown out the door. So, the technology is there.
It's one of the things that we're recommending to organizations is, don't wait until Microsoft absolutely forces it. Yeah. The infrastructure and components are there.
Start making the migration now, today, so that you can get out ahead of it. And so yes, Microsoft will have shifts and pulls and pushes in their timing of these things, but it's really going one way. They're locking down the operating system for security.
They have to. They have to. They have to.
Yeah. This is part of the discussion. No one's here to bash them or not.
This needs to be done, right? It does. And if it means migrating up from 10 to 11, so be it.
Right? Because if you move to Apple, look, Apple's newest version coming out. Completely different.
Right? Yep. And they're not going to support the Intel-based Macs with this next release.
You got an Intel-based Mac, you can't upgrade. You're done. Yeah.
So, that's the world we're living in. Anyway, Kevin, it was great having you on here. I appreciate it.
Thanks, Alan. I appreciate it. Interesting stuff.
So many of the things we take for granted, we don't really, really think about, unless you're a security guy or gal. And then it's like, ooh, that friendly printer becomes just another potential vampire at night or something. Yeah.
One of the nuances of this is printing is so familiar that it's invisible. Exactly. And part of our aim is- No one thinks ...
how do we make the familiar more visible? Because you're exactly right. That's where the security hackers and attackers go.
Always has been. Places that are hidden. Yep.
Yeah. Can't defend what you don't know. All right.
Yeah. Hey, Kevin. Good luck to you.
Keep us posted. Thanks for coming here on Tech StrongTV. Thanks, Alan.
Appreciate it. All right. Hey, we're going to be back with more in just a moment.