3 ms·
Maybe UK (and everyone else) needs a law that requires anyone manufacturing an Internet-connected device to set unique passwords or force users to change the pa
by antattack 5y ago
Maybe UK (and everyone else) needs a law that requires anyone manufacturing an Internet-connected device to set unique passwords or force users to change the password before they can use it, like California's (SB-327).
- Anthony-G 5y agoFrom the featured article: > The government plans to ban default passwords being pre-set on devices, as part of upcoming legislation covering smart devices.
- LocalH 5y agoI hope that only mean they plan to ban non-unique default passwords, rather than requiring users to set up their own password during setup. The latter is a sure-fire ticket to tons of “password” “12345678” “11111111” type passwords.
- mgerdts 5y agoSB-327 says: it shall be deemed a reasonable security feature under subdivision (a) if either of the following requirements are met: (1) The preprogrammed password is unique to each device manufactured. I read this as a password based on the mac address or serial number would be compliant without meeting what I think is the intent of this law.