Live data from Hacker News

Tougher rules for sellers of internet-enabled devices in the UK

bbc.co.uk

21–30 of 71 posts

Re: Tougher rules for sellers of internet-enabled devices in the UK

#21
post #14

Earlier quoted context omitted.

> that manufacturers and retailers inform customers how long they will receive support, including software updates, for the device they are buying and importers. This is the usual requirement in UK law for anything like this (e.g. safety, manufacturing defects). Retailers are responsible for what they sell, and importers are responsible for what they import. If you buy it on credit the credit provider (e.g. a credit…

This is what the Brexit contras were warning for. The UK will still have to follow EU law, because they want to sell stuff in the EU. They just lost their voice in the process to write law

This is ultimately a good thing since UK politicians are mostly selected for by class. It's good for the EU that these useless eaters don't get to write legislation.

Re: Tougher rules for sellers of internet-enabled devices in the UK

#22
post #2

While this move is clearly sensible the number of people importing absolute junk from Temu/AliExpress/Shein means millions of homes will be exploitable regardless.

Darwin at work?

I was typing on my phone, the word 'explosive' was accidental but definitely fits in with the theme of crappy electronics!

I edited the original post.

Re: Tougher rules for sellers of internet-enabled devices in the UK

#23

We had to recently look at this as we sell our product in the UK. The rules are really quite pissweak. From the article: * that password procedures are more secure, including ensuring any set by the manufacturer are not left blank or using easy-to-guess choices like "12345" or "admin" Reasonable. But that's a _really_ low bar. * that there is clarity around how to report "bugs" or security problems that arise i.e. an…

> Reasonable. But that's a _really_ low bar.

... one that even companies like Cisco routinely fail [1], and completely forget about chinesium "smart" devices where the extra 10 cents to provision a unique local password and print it on a label would ruin the profit margin.

> which means nothing if the manufacturer goes bankrupt.

Yep but now customers can hold the seller accountable if that is violated, which will lead sellers and importers to either demand a cash escrow from vendors to account for dealing with refunds should the vendor go bankrupt or that there will be some sort of code escrow industry formed, similar to insurance - should the vendor go bankrupt or cease support prior to the communicated date, the code escrow will release the source code to the sellers/importers so that they can do firmware updates on their own.

[1] https://www.tomshardware.com/news/cisco-backdoor-hardcoded-a...

Re: Tougher rules for sellers of internet-enabled devices in the UK

#24
post #14

Earlier quoted context omitted.

> that manufacturers and retailers inform customers how long they will receive support, including software updates, for the device they are buying and importers. This is the usual requirement in UK law for anything like this (e.g. safety, manufacturing defects). Retailers are responsible for what they sell, and importers are responsible for what they import. If you buy it on credit the credit provider (e.g. a credit…

Can you explain the credit thing? Surely a credit provider is just lending you money? Money is fungible. If I have £100 already, and someone lends me an extra £100, and then I buy two things that both cost £100, and one of them is faulty, how do we determine whether the credit provider is responsible?

There are some extra protections on credit card purchases that you don't get from buying things with cash/debit cards

https://www.moneysupermarket.com/credit-cards/guide-to-credi...

Re: Tougher rules for sellers of internet-enabled devices in the UK

#25
post #12

Earlier quoted context omitted.

Much of the time the Aliexpress products provide the same functionality for far less than Western brands. Sometimes even a bit more functionality. But I'm still a bit wary of mains-connected ones.

Likewise. Connecting to the mains is my main red-line on what I've prepared to buy from unknown brands with names that were pulled from a scabble bag.

I'd add lithium batteries to the list. There's no way short of a teardown you can verify what battery vendor, which quality grade and especially which kind of protection circuitry was used - and even if there's analysis videos from youtubers available, there is no guarantee that the manufacturers haven't swapped stuff around during production runs to account for price and availability changes, or that the manufacturer doesn't suffer from supply chain issues.

Granted, established brands can be similarly impacted, but unlike some alphabet-soup dropshipper from Amazon, brands like Anker, Samsung, Apple or the likes have an actual reputation to lose so their incentive to keep safety in mind is way higher (and yes, even they can fail, both Samsung and Apple had their bad battery issues in the past).

Re: Tougher rules for sellers of internet-enabled devices in the UK

#26

Earlier quoted context omitted.

This is what the Brexit contras were warning for. The UK will still have to follow EU law, because they want to sell stuff in the EU. They just lost their voice in the process to write law

It was 95%* about immigration so none of those arguments mattered * number pulled from my behind. But it was surely very high

It was about brown people. Always is. They aren't bothered by white immigrants.

Re: Tougher rules for sellers of internet-enabled devices in the UK

#27
post #26

Earlier quoted context omitted.

It was 95%* about immigration so none of those arguments mattered * number pulled from my behind. But it was surely very high

It was about brown people. Always is. They aren't bothered by white immigrants.

Kinda. I think it's slowly becoming more anti immigration in general.

Though with the London Mayoral election on Thursday, it seems like people want Khan out, using "ULEZ" as the excuse for not wanting a "brown" person. I know a fair few people who live in London and their only criticism of him is ULEZ, even if it doesn't effect them at all (massively brainwashed by Facebook)

Re: Tougher rules for sellers of internet-enabled devices in the UK

#28
post #26

Earlier quoted context omitted.

It was 95%* about immigration so none of those arguments mattered * number pulled from my behind. But it was surely very high

It was about brown people. Always is. They aren't bothered by white immigrants.

I'm not sure that's entirely true in the UK. The Polish plumber taking British jobs is a fairly common trope in far-right discourse. I believe this is prevalent across Western Europe in general.

Re: Tougher rules for sellers of internet-enabled devices in the UK

#29
post #28
post #26

Earlier quoted context omitted.

It was about brown people. Always is. They aren't bothered by white immigrants.

I'm not sure that's entirely true in the UK. The Polish plumber taking British jobs is a fairly common trope in far-right discourse. I believe this is prevalent across Western Europe in general.

How I long for a Polish plumber. Hard workers, better skilled, better value.

Re: Tougher rules for sellers of internet-enabled devices in the UK

#30
The law itself says very little about what products do - it works similarly to other laws around machines and devices, where the heavy lifting is relegated to industry accepted standards. This is how CE marking (and the somewhat stalled UKCA mark) works - the law says you have to show that your device complies with industry standards, you produce a bunch of documentation showing this, you can give it a CE mark. It's all self-certified - there's no central body which will check.

It was surprisingly hard to work out the actual standards you need to comply with. It seems it's mostly ETSI EN 303 645, which is an IoT security standard for consumer devices. This is actually a fairly pragmatic checklist of things your device should do. It's a good thing this is now mandated by law. You can see the standard here: https://www.etsi.org/deliver/etsi_en/303600_303699/303645/02...

There's an ARM "Platform Security" framework which cross-checks against that standard - so if you can tick all their boxes you're compliant with the law. https://www.arm.com/architecture/psa-certified

It's nice that this standard is openly available - so many of the standards you must comply with to legally sell a product in the EU are hidden behind expensive paywalls. It's absurd that complying with EU and UK law requires paying a 3rd party sometimes hundreds of Euros.

Post reply on HN