Jump to content

Recommended Posts

Posted

The government is planning to introduce new regulations on consumer IoT devices, so that the 'S' in IoT might actually stand for security after all.

 

From https://www.gov.uk/government/news/government-to-strengthen-security-of-internet-connected-products:

 

The plans, drawn up by the Department for Digital, Culture, Media and Sport (DCMS), will make sure all consumer smart devices sold in the UK adhere to the three rigorous security requirements for the Internet of Things (IoT).

 

These are:

 

All consumer internet-connected device passwords must be unique and not resettable to any universal factory setting

 

Manufacturers of consumer IoT devices must provide a public point of contact so anyone can report a vulnerability and it will be acted on in a timely manner

 

Manufacturers of consumer IoT devices must explicitly state the minimum length of time for which the device will receive security updates at the point of sale, either in store or online

Posted
All consumer internet-connected device passwords must be unique

Cool

and not resettable to any universal factory setting

Not so cool if you are the user and forgot the password.

Posted (edited)
and not resettable to any universal factory setting

 

So what happens if you want to sell a device, you cannot give it a default password so you end up giving it a password which then you need to communicate to the new owner and hope they change the password :confused: ,

Edited by Davit2005
Posted
Not so cool if you are the user and forgot the password.

This is handled by devices resetting to their own individual original password, printed in documentation or physically on the device (like your router etc...).

 

There's no need for a single universal username/password.

  • Thanks 1
Posted
This is handled by devices resetting to their own individual original password, printed in documentation or physically on the device (like your router etc...).

 

There's no need for a single universal username/password.

 

If there is a universal unique factory reset username and password, that's fine then. ;)

Posted
I think the really good one is the one about making clear to the consumer what the minimum support lifecycle is for a device. I suspect that might lead manufacturers adopting similar tactics to SONOS, who've built in the option to remotely engage brick-mode once they know that a user has replaced a device.
Posted
This is handled by devices resetting to their own individual original password, printed in documentation or physically on the device (like your router etc...).

 

There's no need for a single universal username/password.

 

That would be ideal

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...