News: 1629735725

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

European Commission airs out new IoT device security draft law – interested parties have a week to weigh in

(2021/08/23)


Infosec pros and other technically minded folk have just under a week left to comment on EU plans to introduce new regulations obligating consumer IoT device makers to address online security issues, data protection, privacy and fraud prevention.

Draft [1]regulations applying to "internet-connected radio equipment and wearable radio equipment" are open for public comment until 27 August – and the resulting laws will apply across the bloc from the end of this year, according to the EU Commission.

Billed as assisting Internet of Things device security, the new regs will apply to other internet-connected gadgets in current use today, explicitly including "certain laptops" as well as "baby monitors, smart appliances, smart cameras and a number of other radio equipment", "dongles, alarm systems, home automation systems" and more.

[2]

"The key objective of this initiative is to contribute to strengthen the 'ecosystem of trust' which stems from the synergies of all related pieces of EU law concerning protection of networks, privacy and against fraud," said the explanatory note on the draft EU regulation, a summary of which is downloadable via the link above.

[3]

[4]

"This initiative should then allow on the EU market only the radio equipment that is sufficiently secure."

The Netherlands' FME association has already [5]raised public concerns about the scope of the EU's plans, specifically raising the "feasibility of post market responsibility for cybersecurity".

[6]

The trade association said: "If there is a low risk exploitable vulnerability; at what level can the manufacturer not release or delay a patch, and what documentation is required to demonstrate that this risk assessment was conducted with this outcome of a very low risk vulnerability?"

While there are certainly holes that can be picked in the draft regs, cheap and cheerful internet-connected devices pose a real risk to the wider internet because of the ease with which they can be hijacked by criminals.

[7]Hard to believe but Congress just approved an IoT security law and it doesn't totally suck

[8]UK.gov wants mobile makers to declare death dates for their new devices from launch

[9]GCHQ asks tech firms to pretty please make IoT devices secure

[10]Remote code execution flaws lurk in countless routers, IoT gear, cameras using Realtek Wi-Fi module SDKs

[11]We need to talk about criminal adversaries who want you to eat undercooked onion rings

[12]Nurserycam horror show: 'Secure' daycare video monitoring product beamed DVR admin creds to all users

The proposed EU regs are similar to those [13]being floated in the UK to tighten up IoT security; rules which were also [14]suddenly widened to cover mobile phones and tablets . Previously the legislation had been sold as a way of securing otherwise painfully insecure IoT devices; GCHQ offshoot the National Cyber Security Centre, a major sponsor of the Secured by Design initiative, [15]may have had the Mirai botnet in mind .

Identity management firm Sectigo's CTO Jason Soroko told The Register , in an interview about botnets and router security, that poor security in these devices stems from industry design choices intended to ease deployment, use and configuration: "If you and I right now, were to investigate the top five latest [routers], would we find a huge difference in terms of how they're built? Would we find open Telnet ports? I bet you we would. Would we find vulnerabilities in terms of weak credential form factors for PHP web interface code?"

Soroko thought the answer was obvious. Certain router makers have learned the hard way that end-of-life equipment that contain insecurities [16]can have a reputational as well as security impact . That said, it's perhaps unreasonable to expect kit makers to keep providing software patches for years after they've stopped shipping a device. Consumers cannot rely on news outlets shaming makers of internet-connected goods into providing better security; new laws are the inevitable next stage, and there's [17]a growing push for them on both sides of the Atlantic .

[18]

Device makers being banned from selling in the EU over security and data protection issues is not new. In 2017, the German telecoms regulator [19]banned the sale of children's smartwatches that allowed users to secretly listen in on nearby conversations and later that year, the French data protection agency [20]issued a formal notice to a biz peddling allegedly insecure Bluetooth-enabled toys – Genesis Toys' My Friend Cayla doll and the i-Que robot, because the doll could be misused to eavesdrop on kids. The manufacturers are also obliged to comply with the GDPR. However, the new draft law is evidence that certain loopholes might soon begin to close. ®

Get our [21]Tech Resources



[1] https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/2018-Internet-connected-radio-equipment-and-wearable-radio-equipment_en

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/edgeiot&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YSQaoNaWjC2TH3joErcIFQAAARA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/edgeiot&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YSQaoNaWjC2TH3joErcIFQAAARA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/edgeiot&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YSQaoNaWjC2TH3joErcIFQAAARA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/2018-Internet-connected-radio-equipment-and-wearable-radio-equipment/F2666836_en

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/edgeiot&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YSQaoNaWjC2TH3joErcIFQAAARA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2020/11/18/us_iot_security/

[8] https://www.theregister.com/2021/04/21/ukgov_death_dates_smartphones_iot_security/

[9] https://www.theregister.com/2018/10/15/iot_security_gchq_ncsc/

[10] https://www.theregister.com/2021/08/16/realtek_wifi_sdk_vulnerabilities/

[11] https://www.theregister.com/2021/04/20/cisco_talos_corosi_fryer_flaws/

[12] https://www.theregister.com/2021/02/18/nurserycam_security_problems_footfallcam_ltd/

[13] https://www.theregister.com/2020/01/28/uk_government_cracks_down_on_iot_security/

[14] https://www.theregister.com/2021/04/21/ukgov_death_dates_smartphones_iot_security/

[15] https://www.theregister.com/2019/03/19/mirai_botnet_new_tricks/

[16] https://www.theregister.com/2021/05/06/which_router_survey/

[17] https://www.theregister.com/2020/11/18/us_iot_security/

[18] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/edgeiot&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YSQaoNaWjC2TH3joErcIFQAAARA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[19] https://www.theregister.com/2017/11/20/kids_smartwatches_branded_secret_spyware_slapped_with_ban_in_germany/

[20] https://www.theregister.com/2017/12/04/creepy_cayla_doll_breaches_french_data_protection_rules_says_agency/

[21] https://whitepapers.theregister.com/



"The Netherlands' FME association has already raised public concerns"

LDS

That's why wolves should not set the rules for the sheep.

Long overdue: a stupid prize for the stupid games these marketers were playing

Alpharious

No one asked for toys to be connected to the internet. This was just an excuse to: spy on kids, put drm in toys, and force dlc down parents throats. I hope this permanently kills the iot market. If regulation does not destroy the consumer IOT market, it will be a psychopath user who does.

How about an EU publicity campaign.........

Anonymous Coward

.....to tell people what they are getting into?

*

1. For example, every IoT device RELIES on a server somewhere which is recording FOR EVER everything that goes on on the IoT device? How may people know this?

*

2. Even if GDPR applies to item #1, how many people know A) who to call and B) what to say......if they want their personal data deleted?

*

3. Ah!!....deleted!!!! What does this mean? Deleted from live databases? Deleted from ALL backups? Deleted from the data exfiltrated by a hack by "bad guys"?

*

Yup.....it's pretty clear that the general public have NO IDEA what they are getting into with the average IoT device!! I think they should be told!!!

Gene Cash

it's perhaps unreasonable to expect kit makers to keep providing software patches for years after they've stopped shipping a device

Why? I don't see why people should be allowed to lob shit into the market and wash their hands of things.

I think if companies were required to provide 3 years of security updates, this would stop cheap garbage marketed on a razor-thin margin.

toejam++

Agreed. If anything, companies that release internet-connected devices should be on the hook for resolving major security vulns for the generally useful lifetime of the device. It should also be setup in such a way that they cannot just shut down or orphan their subsidiary in an attempt to wash their hands of the situation.

Don't lose
Your head
To gain a minute
You need your head
Your brains are in it.
-- Burma Shave