• timlyo
    link
    fedilink
    42 months ago

    Brands have to publish contact details so that bugs and issues can be reported, and must be transparent about timings of security updates.

    The non headline part of the law sounds great to me.

    • @[email protected]
      link
      fedilink
      English
      2
      edit-2
      2 months ago

      Yeah I read the headline and thought what, then read the article and it actually seems pretty reasonable.

      Devices should not come with a username of ‘admin’ and a password of ‘admin’, it’s a disaster waiting to happen.

      • @[email protected]
        link
        fedilink
        English
        12 months ago

        Is it really on the device manufacturer that people don’t change the default password? That’s advice that’s been around so long and it’s the first thing they tell you in computer training.

        Default passwords have their use cases for testing, ease of set-up, and for device recovery.

        • @[email protected]
          link
          fedilink
          English
          3
          edit-2
          2 months ago

          Yes, it should be. Sending someone a device with usr/pwd as admin/admin, for example, is completely reckless if it doesn’t prompt the user to change it during setup.

          it’s the first thing they tell you in computer training.

          You shouldn’t need specialist training to use basic home products, and you shouldn’t have to put up with extremely compromised security in the event of you not being technically-minded or you blitz through installations pressing next next next. Not everyone is or can be technically minded.

          Plenty of products have protections in place designed to protect users in the realistic event that not everything will be used flawlessly 100% of the time.

          PCs aren’t shipped to you with always-on root-level access, gas hobs often have features to turn themselves off if they detect they’ve not been ignited, cars have all kinds of safety features, pills come in pop-packs to discourage taking a load at once by swigging a bottle, Switch cartridges taste like shit to stop babies from choking on them, etc. sure, not all of these should be legally required, but some absolutely should be.

      • andrew
        link
        fedilink
        English
        1
        edit-2
        2 months ago

        Something I have: my luggage

        Something else I have: bolt cutters

        It’s an expensive system but it works for me.

  • Bahnd Rollard
    link
    fedilink
    English
    22 months ago

    12345? Thats amazing, I have the same combination on my luggage!

  • @[email protected]
    link
    fedilink
    English
    12 months ago

    This should already be in place with a lot of products due to a California law effective in 2020.

  • @[email protected]
    link
    fedilink
    English
    12 months ago

    I assumed each device would be programmed with the top 5,000 most common passwords which it would refuse.

    And the device would nag the administrator to change the password away from the default as soon as possible, please.

  • @[email protected]
    link
    fedilink
    English
    -1
    edit-2
    2 months ago

    Usually, an impact study is made before such type of laws are made:

    • if this law is enacted, how much will it cost to the manufacturers to update their factory settings?
    • how will this be impacted on the device cost in the UK compared to other markets?
    • how many users will get stuck when losing the unique ID of the device, what are the recovery procedures, how costly is it to end users?
    • how many users will be protected by the measure and what cost for society does it represent?
    • how many users will set a dumb password anyhow and what is the cost for society?

    I’d be curious to see the impact study, as many of those are actually botched.

    • magic_lobster_party
      link
      fedilink
      12 months ago

      Most routers already have non-standard passwords by default. At least in EU. I’m not sure which devices besides routers and IoT peripherals are affected by this bill.

    • metaStatic
      link
      fedilink
      12 months ago

      a user set weak password is infinitly more strong than a known default.

      admin
      admin

  • @[email protected]
    link
    fedilink
    English
    -12 months ago

    I like the easy default passwords for when I’m setting stuff up. If the end user doesn’t change it, that’s on them. This is one of those laws that just inconveniences the 90% to protect the lazy/stupid 10%.

  • @[email protected]OP
    link
    fedilink
    English
    -1
    edit-2
    2 months ago

    How they know what password we use in our device ? Do they scan our device without our permission ?