UK becomes first country to ban default bad passwords on IoT devices
therecord.media
therecord.media
(2) Passwords must be—
(a)unique per product; or
(b)defined by the user of the product.
(3) Passwords which are unique per product must not be—
(a)based on incremental counters;
(b)based on or derived from publicly available information;
(c)based on or derived from unique product identifiers, such as serial numbers, unless this is done using an encryption method, or keyed hashing algorithm, that is accepted as part of good industry practice;
(d)otherwise guessable in a manner unacceptable as part of good industry practice. “unique per product” means unique for each individual product
of a given product class or type.
Overall, why not just require random passwords of a certain length? Compared to generating a hash, generating a random password is easier (no data input, such as the serial number, is needed) and no less user-friendly.Or, define it in terms of entropy? Maybe that kind of technicality is too hard to understand.
It might be the first country, but as far as I know, not the first place to do that; I've read at https://www.servethehome.com/why-your-favorite-default-passw... that one state of another country has already implemented a similar law.
Default passwords in 'smart' devices now banned in UK (https://news.ycombinator.com/item?id=40195841) - (no comments)
if my past passwords can be examined for comparison with a current one, i cant shake the idea that no password is secret under such a regime
i suppose an "evil admin" has a lot of other ways to harvest passwds, rather than one that is a major security problem.
Really? The law doesn't even contain the word "password", let alone ban any.
This seems to be bullshit.