jthompson Posted January 28, 2020 Posted January 28, 2020 The government is planning to introduce new regulations on consumer IoT devices, so that the 'S' in IoT might actually stand for security after all. From https://www.gov.uk/government/news/government-to-strengthen-security-of-internet-connected-products: The plans, drawn up by the Department for Digital, Culture, Media and Sport (DCMS), will make sure all consumer smart devices sold in the UK adhere to the three rigorous security requirements for the Internet of Things (IoT). These are: All consumer internet-connected device passwords must be unique and not resettable to any universal factory setting Manufacturers of consumer IoT devices must provide a public point of contact so anyone can report a vulnerability and it will be acted on in a timely manner Manufacturers of consumer IoT devices must explicitly state the minimum length of time for which the device will receive security updates at the point of sale, either in store or online
DJ-1701 Posted January 28, 2020 Posted January 28, 2020 All consumer internet-connected device passwords must be unique Cool and not resettable to any universal factory setting Not so cool if you are the user and forgot the password.
Davit2005 Posted January 28, 2020 Posted January 28, 2020 (edited) and not resettable to any universal factory setting So what happens if you want to sell a device, you cannot give it a default password so you end up giving it a password which then you need to communicate to the new owner and hope they change the password , Edited January 28, 2020 by Davit2005
localzuk Posted January 28, 2020 Posted January 28, 2020 Not so cool if you are the user and forgot the password. This is handled by devices resetting to their own individual original password, printed in documentation or physically on the device (like your router etc...). There's no need for a single universal username/password. 1
DJ-1701 Posted January 28, 2020 Posted January 28, 2020 This is handled by devices resetting to their own individual original password, printed in documentation or physically on the device (like your router etc...). There's no need for a single universal username/password. If there is a universal unique factory reset username and password, that's fine then.
jthompson Posted January 28, 2020 Author Posted January 28, 2020 I think the really good one is the one about making clear to the consumer what the minimum support lifecycle is for a device. I suspect that might lead manufacturers adopting similar tactics to SONOS, who've built in the option to remotely engage brick-mode once they know that a user has replaced a device.
Davit2005 Posted January 28, 2020 Posted January 28, 2020 This is handled by devices resetting to their own individual original password, printed in documentation or physically on the device (like your router etc...). There's no need for a single universal username/password. That would be ideal
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now