Ban Bad Default Passwords On IoT Kit? Don’t Mind If You Do!
Hopefully The UK Is Just The First Of Many
There are many frustrating things about how companies treat the security of the IoT kit they sell, and the UK is addressing two of the biggest. The first is the tendency to be lazy about passwords, as companies will often sell an entire line of products that all have the same password. Even better, the password is usually something awful like admin, or it’s simply blank. That is now illegal in the UK and companies found ignoring the new law will be subject to a fine of £10 million ($12.53 million) or 4% of their global revenue, which ever is higher. The product would also be subject to a complete recall.
The second thing this law addresses is the practice of companies to simply abandon IoT devices with little to no notice. This is often because the company switched to selling a newer model, but occasionally it is because of an bug that is hard to patch, if not impossible to get rid of. The new law requires companies to be transparent about the length of time the devices will receive security updates. This may hopefully help consumers make informed decisions when buying their next Internet attached fish tank thermometer or doorbell camera.
The Product Security and Telecommunications Infrastructure Act 2022 (PSTI) introduces new minimum-security standards for manufacturers, and demands that these companies are open with consumers about how long their products will receive security updates for.
More Tech News From Around The Web
- Google rejected 2.28 million risky Android apps from Play store in 2023 @ Bleeping Computer
- Microsoft fixes bug behind incorrect BitLocker encryption errors @ Bleeping Computer
- Raspberry Pi adds more memory to the Compute Module 4S @ The Register
- First post: A history of online public messaging @ Ars Technica
- The eight-bit Z80 is dead. Long live the 16-bit Z80! @ The Register
- The Naked-Eye Sky Will (Briefly) Host a New Star @ Slashdot
- ASRock Rack MT710-2T2O 10GbE OCP NIC 3.0 @ ServeTheHome