International NewsNewsPoliticsTech News

United Kingdom Becomes First Country to Ban Easily Guessable Default Passwords on Consumer Smart Devices

On April 29, 2024, the United Kingdom became the first country to make easily guessable default passwords on consumer smart devices a legal problem, not a user problem. The Product Security and Telecommunications Infrastructure Act does not ban every factory password. It bans the ones everyone already knows: admin, 12345, the string printed in a PDF on the manufacturer’s website. A device can still ship with a credential if that credential is unique to the unit, or if setup forces the buyer to set their own.

Two other rules sit next to the password ban. Makers must publish a way for researchers and owners to report holes. They must also say, in public, how long the gadget will get security updates. Those three lines track the ETSI EN 303 645 standard that has become the global IoT floor. The Office for Product Safety and Standards, inside the Department for Business and Trade, enforces it. The fine is up to £10 million or 4 percent of worldwide turnover, whichever is larger. Importers and retailers are in the net, not just the factory in Shenzhen.

Chart of industries hit by DDoS attacks, used in The AEGIS Alliance coverage of the UK ban on default smart-device passwords.
Abstract network graphic illustrating IoT cyber security, in reporting by The AEGIS Alliance on the UK PSTI Act.

The law covers speakers, TVs, doorbells, baby monitors, cameras, tablets, phones, consoles, fitness trackers, bulbs, plugs, kettles, thermostats, ovens, fridges, and washers. The point is Mirai. Cloudflare’s first-quarter 2024 DDoS report still had Mirai variants behind about four in 100 HTTP attacks and two in 100 network-layer attacks, years after the original botnet was dismantled. Default passwords are how those botnets are born.

A Floor, Not an Island

California banned weak defaults in a 2018 law that took effect in 2020. Manufacturers do not like building a special insecure version for one country, so a hard rule in a big market tends to raise the floor everywhere. The EU Cyber Resilience Act is scheduled to bite across the bloc by 2027. The United States has a voluntary Cyber Trust Mark. Australia’s Cyber Security Bill 2024 looks a lot like PSTI. The UK’s NCSC has said it is «highly likely» the rules will later cover business kit, not just the junk in the living room.

How Is The UK’s PSTI Act Making IoT Devices Safer?

The same week PSTI took effect, Citizen Lab showed what happens when the encryption on the keyboard itself is junk. The AEGIS Alliance covered that pinyin-app leak of nearly a billion users’ keystrokes. For more, see Tech News and International News. Official guidance lives at the UK National Cyber Security Centre.

The AEGIS Alliance U.K.
Bringing you news from the United Kingdom and greater Europe! Journalist, editor, activist, social media management, content creator. Based in the U.K.

Publicaciones relacionadas

Botón volver arriba
Signup for our news and memes newsletters! 

Newsletter Form

Lists
close-link