UK.gov wants mobile makers to declare death dates for their new devices from launch
- Reference: 1619017510
- News link: https://www.theregister.co.uk/2021/04/21/ukgov_death_dates_smartphones_iot_security/
- Source link:
Today's pledge would see existing plans for internet-connected tat extended to smartphones and tablets, which is a large step for a scheme originally put together for landfill Internet-of-Things devices such as webcams.
[1]
Digital Infrastructure Minister Matt Warman said in a canned statement: "Our phones and smart devices can be a gold mine for hackers looking to steal data, yet a great number still run older software with holes in their security systems."
The £70m Secure by Design plan has been [2]telegraphed by the DCMS for years, though today's extension to everyday smartphones is notable.
On top of this, smart device makers will also be banned from publishing default admin passwords for their wares. Such admin passwords are a standard method for digital crims to break into a device or the network to which it is connected.
[3]
A government-sponsored study from University College London two years ago, highlighted today by DCMS, [4]said typical IoT devices come with no crime prevention advice, which is presumably the sort of finding that UK.gov enjoys seeing public money poured into.
The plans are likely to meet stiff opposition from device makers as end-of-life dates for devices are usually an open secret among the tech-savvy but stating them at the launch of a brand new bit of hardware is unlikely to be popular with manufacturers' marketing teams.
Gov-backed consumer org Which? supported the move, stating: "This must be backed up by strong enforcement, ensuring people can get effective redress when they purchase devices that fail to meet security standards and leave them exposed to data breaches and scams."
[5]
The National Cyber Security Centre's [6]dogfood-munching technical director Ian Levy said in a canned statement: "DCMS' publication builds on the 2018 Code of Practice and ETSI EN 303 645 to clearly outline the expectations on industry. To protect consumers and build trust across the sector, it is vital that manufacturers take responsibility and pay attention to these proposals now."
He added: "It is also important to support uptake of good practice and provide industry with opportunities to innovate. I'm pleased to see the pilots, funded by DCMS, begin to test ways in which customers will be able to gain confidence in the security of these devices." ®
Get our [7]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YIBMFa9k7Faytm9IpiB6TAAAAEw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.theregister.com/2019/01/28/ukgov_secure_by_design_70m_arm_cambridge/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YIBMFa9k7Faytm9IpiB6TAAAAEw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://academic.oup.com/cybersecurity/article/5/1/tyz005/5519411
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YIBMFa9k7Faytm9IpiB6TAAAAEw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.ncsc.gov.uk/blog-post/active-cyber-defence-tackling-cyber-attacks-uk
[7] https://whitepapers.theregister.com/
Re: Force open source instead
@Brian Miller,
I came here to say the same.
If the vendors won't support it, make it free so that we can support it ourselves, or refund the price we paid for it, or give us a free upgrade to the next product that you will support.
We have to get out of the 2 years then land fill approach with technology.
Re: Force open source instead
Better yet, just allow folks to flash whatever the hell they like to their phones and have the warranty cover only the hardware regardless of software.
While they're at it, if they can make the flash chips socketed, that'd be great. I don't care if the socket makes the phone thicker...fill the extra space with more battery.
Just security, or functionality as well?
Would be good if this extends to functional updates as well as security ones.
Annoyingly, I've had to replace phones in the past not because they've worn out or broken, but because the lack of OS updates means apps and things stop working.
Re: Just security, or functionality as well?
It would be nice if end of support or at least minimum support periods were published for all paid for apps, programs and services.
Nowadays the process for bringing out new improved anything has little to do with progress and everything to do with marketing and driving new sales.
Consumers are no longer customers, they are merely a resource to be tapped when a product is superceded by a new one.
Even better, ban the sale of devices without a guaranteed minimum of 5 years' worth of security updates.
Weirdly I actually wouldn't buy a gadget if it only offered 5 years. I also think if people saw a defined "death date" it would reduce the likelyhood of an impulse buy.
Might just be me and the fact that I expect better for my money. I write shite to last more than 5 years, why should I not expect the same?
Force open source instead
Instead of publishing a death date, force the manufacturer to publish the OS as open source, so we don't have to toss a good device into the landfill.
Yeah, I know, that isn't so popular with the manufacturers, either.