California to ban weak default passwords on internet-connected devices
theregister.co.uk
theregister.co.uk
It may slow down the production process, but it's a step in the right direction for security. All this bill means is that manufactures who don't have that process in place can't sell their devices in California. It will probably mean more devices with random passwords for the whole country.
This has been a thing for a while for WLAN routers. But I still don't really trust those, for all I know these passwords could be seeded on something very predictable, like the devices serial number.
If they do it properly then there should be no problem with surfacing their methodology and I'd have less hassle by actually being able to trust those complex individual passwords the device comes with out of the box.
Serial numbers generally have really low entropy. They're often a fixed format assigned sequentially or in batches, which makes attacking them substantially easier.
I shipped firmware for an IoT device, had the initial password == the serial number. The client said "Nah, just make it open, our installers don't want to fool with passwords". Sigh.
And sometimes this sticker is left on the router and can be plainly seen by anyone nearby, even through a glass window.
You are correct, but we shouldn't let perfect be the enemy of good.
Generally device already have their MAC address and serial number both printed on the outside and burned into an EPROM in the device, so printing a password really won’t make much of a difference.
It's not just printing the password. There is also an overhead of configuring the device with a unique password.
This bill, beginning on January 1, 2020, would require a manufacturer of a
connected device, as those terms are defined, to equip the device with a
reasonable security feature or features that are appropriate to the nature
and function of the device, appropriate to the information it may collect,
contain, or transmit, and designed to protect the device and any information
contained therein from unauthorized access, destruction, use, modification,
or disclosure, as specified.
A better title would be "California to ban weak default passwords on devices." Edit: or "California to require more security features on internet-connected devices." Subject to all of the requirements of subdivision (a),
if a connected device is equipped with a means for
authentication outside a local area network, it shall be
deemed a reasonable security feature under subdivision (a)
if either of the following requirements are met:
(1) The preprogrammed password is unique to each device manufactured.
(2) The device contains a security feature that requires
a user to generate a new means of authentication
before access is granted to the device for the first time.
Even this can be weaseled out of for most consumer IoT products as they aren't typically intended for direct access from outside the LAN.Does it? The problem is that they defined a very specific solution to the problem they are trying to solve as comprising of either approach (1) or (2) ... what if there is some innovative third option that neither people here nor the regulators was creative enough to think of? Now you've killed a potential innovative market from developing.
>Even this can be weaseled out of
That's not 'weaseling out'. That's a real world example of an approach that is perfectly secure and would be hurt by this if a regulator interpreted the law as applying to the device in question.
Besides, having weak security on a network means one compromise leads to a lot more. That isn’t very ‘perfectly secure’ either.
For "cloud-only IoT devices" this ban is clearly in effect.
Quoted text are hard to read on HN. It's impossible to read without multiple horizontal scrolling both on PC an mobile. Just use the ">" symbol instead.
> This bill, beginning on January 1, 2020, would require a manufacturer of a connected device, as those terms are defined, to equip the device with a reasonable security feature or features that are appropriate to the nature and function of the device, appropriate to the information it may collect, contain, or transmit, and designed to protect the device and any information contained therein from unauthorized access, destruction, use, modification, or disclosure, as specified.
EDIT: added Unicode name for ^.
California requires manufacturers use better password security measures.
But that is boring... so
California bans manufacturers from setting weak passwords
(this title creation job is hard enough for a technical person to do. journalists will have a more difficult time.)
Also, it is not a good idea for lawmakers and regulators to mandate an implementation within a law (and that's exactly what mandating that per-device password needs to be unique is). Maybe my IoT device has a simple default password but has other security measures that the regulator didn't even envision that makes the solution secure. On the other end, maybe my network stack has a critical vulnerability that a unique password does nothing to mitigate.
I'm not a Libertarian as I do believe in sensible government oversight and regulation but lawmakers and regulators have to be cognizant that every single regulation they put out has a cost and that cost needs to be balanced with benefits. As it stands this is a poorly thought out law, and will do nothing for security, will punish local manufacturers by increasing overhead, and will make local manufacturers less competitive against external ones that simply ignore these directives. Typical California stupidness.
I agree it would be better if industry self-regulated. But they didn't. e.g.: https://www.bleepingcomputer.com/news/security/router-crapfe...
If this were a problem where only the device owners were harmed, I wouldn't care a lot. Market mechanisms would take care of it. But here bad vendor security is imposing large negative externalities on the rest of the world. If government is for anything at all, it's for making people experience the consequences of their own actions instead of inflicting harm on others. This is not a perfect regulation, but it's better than nothing. Hopefully device-makers will take this as a warning shot a and get their acts together.
Well. They don't. This law is an example.
>but it's better than nothing.
No. It's worse than nothing, and that's the point. It will do nothing to improve security and but leave the associated burden that wasn't there before.
Is CA a major location for router manufacturing?
Ugh. :(