United Kingdom Becomes First Country to Ban Easily Guessable Default Passwords on Consumer Smart Devices
On April 29, 2024, the United Kingdom became the first country to make easily guessable default passwords on consumer smart devices a legal problem, not a user problem. The Product Security and Telecommunications Infrastructure Act does not ban every factory password. It bans the ones everyone already knows: admin, 12345, the string printed in a PDF on the manufacturer’s website. A device can still ship with a credential if that credential is unique to the unit, or if setup forces the buyer to set their own.
Two other rules sit next to the password ban. Makers must publish a way for researchers and owners to report holes. They must also say, in public, how long the gadget will get security updates. Those three lines track the ETSI EN 303 645 standard that has become the global IoT floor. The Office for Product Safety and Standards, inside the Department for Business and Trade, enforces it. The fine is up to £10 million or 4 percent of worldwide turnover, whichever is larger. Importers and retailers are in the net, not just the factory in Shenzhen.


The law covers speakers, TVs, doorbells, baby monitors, cameras, tablets, phones, consoles, fitness trackers, bulbs, plugs, kettles, thermostats, ovens, fridges, and washers. The point is Mirai. Cloudflare’s first-quarter 2024 DDoS report still had Mirai variants behind about four in 100 HTTP attacks and two in 100 network-layer attacks, years after the original botnet was dismantled. Default passwords are how those botnets are born.
A Floor, Not an Island
California banned weak defaults in a 2018 law that took effect in 2020. Manufacturers do not like building a special insecure version for one country, so a hard rule in a big market tends to raise the floor everywhere. The EU Cyber Resilience Act is scheduled to bite across the bloc by 2027. The United States has a voluntary Cyber Trust Mark. Australia’s Cyber Security Bill 2024 looks a lot like PSTI. The UK’s NCSC has said it is «highly likely» the rules will later cover business kit, not just the junk in the living room.

The same week PSTI took effect, Citizen Lab showed what happens when the encryption on the keyboard itself is junk. The AEGIS Alliance covered that pinyin-app leak of nearly a billion users’ keystrokes. For more, see Tech News and International News. Official guidance lives at the UK National Cyber Security Centre.









