Live data from Hacker News

Tougher rules for sellers of internet-enabled devices in the UK

bbc.co.uk

1–10 of 71 posts

Re: Tougher rules for sellers of internet-enabled devices in the UK

#3
> that manufacturers and retailers inform customers how long they will receive support, including software updates, for the device they are buying

This is important. I noticed Epson publishing information on the length of support for their printers already.

Re: Tougher rules for sellers of internet-enabled devices in the UK

#4
We had to recently look at this as we sell our product in the UK. The rules are really quite pissweak. From the article:

* that password procedures are more secure, including ensuring any set by the manufacturer are not left blank or using easy-to-guess choices like "12345" or "admin"

Reasonable. But that's a _really_ low bar.

* that there is clarity around how to report "bugs" or security problems that arise

i.e. an email address published on the vendor website. No actual requirement to take action.

* that manufacturers and retailers inform customers how long they will receive support, including software updates, for the device they are buying

which means nothing if the manufacturer goes bankrupt.

Re: Tougher rules for sellers of internet-enabled devices in the UK

#5
It's a greatly diluted version of article relative to IoT from the European Cybersecurity Act (Regulation (E.U.) 2019/881 of April 17 2019), 4 years after everyone.

https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELE...

Nothing new or interesting. If the products were already on the market in the European Union, they had already been subject to stricter requirements for 4 years.

The only change is that seller now have to display this information in the UK, whereas before they were not obliged to do so.

Re: Tougher rules for sellers of internet-enabled devices in the UK

#6

We had to recently look at this as we sell our product in the UK. The rules are really quite pissweak. From the article: * that password procedures are more secure, including ensuring any set by the manufacturer are not left blank or using easy-to-guess choices like "12345" or "admin" Reasonable. But that's a _really_ low bar. * that there is clarity around how to report "bugs" or security problems that arise i.e. an…

I think the third one has no effect on startups but it could have a big effect on for e.g. the Google's of this world who buy small companies then kill their product line or end support after a couple of years.

Re: Tougher rules for sellers of internet-enabled devices in the UK

#8

We had to recently look at this as we sell our product in the UK. The rules are really quite pissweak. From the article: * that password procedures are more secure, including ensuring any set by the manufacturer are not left blank or using easy-to-guess choices like "12345" or "admin" Reasonable. But that's a _really_ low bar. * that there is clarity around how to report "bugs" or security problems that arise i.e. an…

Many major brands, particularly in the construction industry, rebrand smart locks, meters, house automation and smart relay equipment of unknown origin with their own brand names. Since they're the ones who put the products on the market, they're the ones who will have to provide maintenance and safety updates, regardless of whether they're an OEM or not.

People were unhappy to discover that their cloud-connected smart lock was no longer working after 2 years. And states don't want to have a large population of vulnerable equipment that could be used to amplify state-sponsored attacks on their national networks.

This is the purpose of the European Cyber Resilience Act.

Re: Tougher rules for sellers of internet-enabled devices in the UK

#9

We had to recently look at this as we sell our product in the UK. The rules are really quite pissweak. From the article: * that password procedures are more secure, including ensuring any set by the manufacturer are not left blank or using easy-to-guess choices like "12345" or "admin" Reasonable. But that's a _really_ low bar. * that there is clarity around how to report "bugs" or security problems that arise i.e. an…

[deleted]

Re: Tougher rules for sellers of internet-enabled devices in the UK

#10

We had to recently look at this as we sell our product in the UK. The rules are really quite pissweak. From the article: * that password procedures are more secure, including ensuring any set by the manufacturer are not left blank or using easy-to-guess choices like "12345" or "admin" Reasonable. But that's a _really_ low bar. * that there is clarity around how to report "bugs" or security problems that arise i.e. an…

Many major brands, particularly in the construction industry, rebrand smart locks, meters, house automation and smart relay equipment of unknown origin with their own brand names. Since they're the ones who put the products on the market, they're the ones who will have to provide maintenance and safety updates, regardless of whether they're an OEM or not. People were unhappy to discover that their cloud-connected sma…

> Since they're the ones who put the products on the market, they're the ones who will have to provide maintenance and safety updates

But these rules make no such requirement.

Post reply on HN