UK law will hit smart home device makers with fines for using default passwords
1–10 of 10 posts
Re: UK law will hit smart home device makers with fines for using default passwords
#2Re: UK law will hit smart home device makers with fines for using default passwords
#3This will end up just being really annoying and accomplish nothing, like most corporate password policies. It would be nice to see a focus on actually solving the problem, instead of the usual liability transfer. Best case scenario, the password is written on a sticker on the device. This is the norm where I live. I would love to see incentives for actual user friendly security enhancements.
Yes, this is expected. The point is to prevent a population of devices being sold with admin/admin pre-programmed.
Re: UK law will hit smart home device makers with fines for using default passwords
#4Re: UK law will hit smart home device makers with fines for using default passwords
#5- manufacturers must tell customers up front about the lifespan of security patches and updates - manufacturers must provide a public point of contact for vulnerability disclosure
Re: UK law will hit smart home device makers with fines for using default passwords
#6If you forget your password to an IoT device, and the paper label on it wore off, is it now mandatory for it to be permanently bricked and instant e-waste?
A lot more convoluted, but you could make a nice CompanyNameDeviceSetup app, which could handle the minutiae.
Re: UK law will hit smart home device makers with fines for using default passwords
#7This is a nice start at standardizing basic IoT device security; other highlights: - manufacturers must tell customers up front about the lifespan of security patches and updates - manufacturers must provide a public point of contact for vulnerability disclosure
Re: UK law will hit smart home device makers with fines for using default passwords
#8If you forget your password to an IoT device, and the paper label on it wore off, is it now mandatory for it to be permanently bricked and instant e-waste?
Not necessarily, you could have a bootstrap operation where pressing a reset button, allows you to pass a public key to the device, which it will use to send back an encrypted new random username/password combo, which you could then log in with. A lot more convoluted, but you could make a nice CompanyNameDeviceSetup app, which could handle the minutiae.
The only (partial) solution I can imagine is someone creating an open-source software for resetting the password to a non-standard setting, then evangelizing the standard. There are a few issues with this, and it would require adding some standard interface (USB or other) to every such device.
Re: UK law will hit smart home device makers with fines for using default passwords
#9This will end up just being really annoying and accomplish nothing, like most corporate password policies. It would be nice to see a focus on actually solving the problem, instead of the usual liability transfer. Best case scenario, the password is written on a sticker on the device. This is the norm where I live. I would love to see incentives for actual user friendly security enhancements.
Re: UK law will hit smart home device makers with fines for using default passwords
#10This will end up just being really annoying and accomplish nothing, like most corporate password policies. It would be nice to see a focus on actually solving the problem, instead of the usual liability transfer. Best case scenario, the password is written on a sticker on the device. This is the norm where I live. I would love to see incentives for actual user friendly security enhancements.
Credential being stored on a sticker on the device does help against the device being remotely enrolled in a ddos/spam botnet.
Having the manufacture make it a permanent part of the device using something like engraving makes it more robust and harder to subvert. Unfortunately as a side effect it increases cost per unit.
The sticker's not that bad, but it depends on the devices usage scenario.