5 ms·
from the press release linked to in the article (https://www.gov.uk/government/news/government-to-strengthen-security-of-internet-connected-products https://www
by flareback 7y ago
from the press release linked to in the article (https://www.gov.uk/government/news/government-to-strengthen-security-of-internet-connected-products https://www.gov.uk/government/news/government-to-strengthen-...):
- All consumer internet-connected device passwords must be unique and not resettable to any universal factory setting
- Manufacturers of consumer IoT devices must provide a public point of contact so anyone can report a vulnerability and it will be acted on in a timely manner
- Manufacturers of consumer IoT devices must explicitly state the minimum length of time for which the device will receive security updates at the point of sale, either in store or online
- jchw 7y agoThis all seems reasonable. Frankly, though, imagine the benefit we would see if this was also enforced for consumer network equipment, like routers...
- bigiain 7y agoMostly reasonable, but shortsighted it seems to me. How do they expect to enforce these requirements on the manufacture of the IoT crap sold by the vendor “Best Security Happiness Store” on AliBaba, and the unnamed (or outright counterfeit named) Chinese manufacturer they bought it from? And conversely, they could obviously easily apply this to the UK based Raspberry Pi foundation, but who’s responsible for enforcing the “no way to reset to a known factory password” for the pi:raspberry login from a stock Rasbian install? (Or do we just hand wave that away and say “that’s not a consumer device, even though we’ve shipped over 30 million of them!”?)
- hakfoo 7y agoI suspect the Raspberry Pi issue is avoided because technically, it doesn't do squat until you install software on it. You might get a preflashed Raspbian card in the box, but I could just as easily be running RiscOS
- jl6 7y agoI don’t see a time limit on that second point. For how long will companies be expected to act upon vulnerability reports? What’s a reasonable end of life?
- jchw 7y agoMy guess is that this is covered by the third point - if you EOL security patches for a device I am guessing you are no longer expected to act on vulnerability reports.