News: 1638436510

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

New UK product security law won't be undercut by rogue traders upping and vanishing, government boasts

(2021/12/02)


Britain's plans to force internet-connected device vendors to declare legally binding product lifespans won't be easily evaded by shell companies, the government has told The Register .

After the Product Security and Telecommunications Infrastructure (PSTI) Bill was introduced to Parliament [1]last week , some questioned whether the legislation would prevent unscrupulous manufacturers and importers from avoiding legal liability by setting up shell companies.

The proposed new law will, so government spokespeople say, make manufacturers, importers, and vendors declare what a product's supported lifespan is to consumers at the point of purchase. In effect this means anyone involved in consumer internet gadget supply chains is offering a form of product support warranty.

[2]

Government intent is to prevent suppliers of cheap IoT gadgets (and mobes 'n' fondleslabs) from dumping them on the UK market and running away without offering security updates if vulnerabilities are later discovered. Product-pwning vulns typically let malicious people turn the pwnable gadget into a botnet component, or worse.

[3]

[4]

A DCMS spokesman told us: "UK regulators are experienced in dealing with rogue traders and these new laws don't just cover distributors but also manufacturers and importers, which will lead to a reduction in the number of insecure products on the market."

Importers and disties will be legally obliged, in some circumstances, to tell their customers (who might not be end-user consumers) that a vuln has been discovered in any internet-connected gizmos they've brought into Britain, as clauses 18(3) and 18(4) of the Bill suggest

[5]PDF

.

[6]UK.gov emits draft IoT and smartphone security law for Parliamentary scrutiny

[7]The Internet of Things is a security nightmare, latest real-world analysis reveals: Unencrypted traffic, network crossover, vulnerable OSes

[8]Hard to believe but Congress just approved an IoT security law and it doesn't totally suck

[9]Research finds consumer-grade IoT devices showing up... on corporate networks

"We are also educating people on the risks of cyber crime, including through our recent CyberAware Black Friday campaign, meaning rogue traders will find it harder to sell substandard products," added the rather optimistic DCMS spokesman.

The PSTI bill will give government figures the power to order product recalls if DCMS believes a particular item breaches minimum UK security standards. Those standards will be created in legally binding regulations intended to be rubberstamped into law as a statutory instrument after the PSTI Bill itself; the bill creates the legal framework that the regulations will flesh out.

[10]

Government has claimed the as-yet-unpublished regulations will ban default admin passwords, among other things.

Some industry sources, who wanted to remain anonymous, told The Register , that if the regulations were not subject to public debate before being nodded through by Parliament, they would set a standard that was too high or costly for IoT device importers and vendors to meet.

We are told by DCMS that failing to comply with an enforcement notice issued under the PSTI bill's regulations will be enforceable against UK-based directors and officers of shell or shadow companies.

[11]

This follows the latest global regulatory trend of demanding companies have a locally incorporated subsidiary before permitting them to do business inside a country, with cynical people characterising this as [12]the taking of local hostages to ensure obedience . ®

Get our [13]Tech Resources



[1] https://www.theregister.com/2021/11/25/product_security_telecoms_bill_parliament/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YainaRxXM511MXeJBQVVHQAAAJI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YainaRxXM511MXeJBQVVHQAAAJI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YainaRxXM511MXeJBQVVHQAAAJI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://publications.parliament.uk/pa/bills/cbill/58-02/0199/210199.pdf#page=16

[6] https://www.theregister.com/2021/11/25/product_security_telecoms_bill_parliament/

[7] https://www.theregister.com/2020/03/11/internet_of_things_security_nightmare/

[8] https://www.theregister.com/2020/11/18/us_iot_security/

[9] https://www.theregister.com/2021/10/21/iot_devices_corporate_networks_security_warning/

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YainaRxXM511MXeJBQVVHQAAAJI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YainaRxXM511MXeJBQVVHQAAAJI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[12] https://restofworld.org/2021/social-media-laws-twitter-facebook/

[13] https://whitepapers.theregister.com/



Laugh

elsergiovolador

So to get around this you just have to find a patsy to act as a director. At best he or she will get extended all inclusive holiday at one of HM resorts.

In other words, what this "product security law" actually bring to the table?

Seems like it will make it more expensive for SMEs and usual suspects will get around it just fine.

Re: Laugh

Anonymous Coward

A DCMS spokesman told us: "UK regulators are experienced in dealing with rogue traders and these new laws don't just cover distributors but also manufacturers and importers, which will lead to a reduction in the number of insecure products on the market."

The same has been pretty much true of EMC compatibility laws for the past 25 years and it has not and does not stop utterly non compliant products reaching the UK. Similarly for basic electrical safety on knock-off products, such as phone chargers.

Real person not needed

Peter Prof Fox

Anyone following the shambles that is the regulation of shell companies and LLPs in Private Eye will know that no checking goes on.

Taking a local hostage

Pascal Monett

Well yes. It's not cynical, it's perfectly normal. In a world where Zuckerberg is free to ignore repeated pleas and demands for making his cash cow more palatable to the concept of morality, it is obvious that one way to make that bastard focus on the issue is to drag the local CEO muppet in front of the beak and make him sweat.

Add a bit of inside pressure to the outside pressure that apparently does nothing at all to His Zuckyness.

And you can put the name of any multinational conglomerate that has a high presence on the web and no stores anywhere in the same basket. Right now we are under the influence of American companies, but nothing says that China, India or even Russia could not, one day soon, have an outrageously successful app on the Internet that is used the world over. When that day comes, we won't have more influence over the makers of that product than we have now over Facebook.

That is not acceptable when the risk is (young) people being stalked or abused.

Re: Taking a local hostage

Yet Another Hierachial Anonynmous Coward

If I am not mistaken, the US courts put the US directors of Volkswagon in prison for their part in the consumer fraud that was dieselgate, whilst the european directors got off with a slap on the wrist or less. International global companies and their CEO's should be held to account wherever that tradename is used or represented..

Phones Sheridan

"will be enforceable against UK-based directors and officers of shell or shadow companies."

So ne'er do wells will do a Facebook, and have no UK based directors or officers.

[1]Current Facebook UK officers

[1] https://find-and-update.company-information.service.gov.uk/company/06331310/officers

We need more laws

Boris the Cockroach

More than the consumer rights act that says that items sold must be fit for use?

So if the software inside said item is bollocks and has a default password of 1234, then the item falls outside the fit for use bit of the aforementioned act.

But then we all know the fun and games that begin when we buy a 2nd hand car from a dealer and it has a fault "they're all like it m8", "I cant hear the noise", "drives ok when we tested it", "Its outside the legal 30 days to fix it time", and of course the final "Ok ok we'll fix it but you'll have to pay for it" when presented with a MOT failure notice from another garage.....

So I dont see any of the IoT tat brigade actually doing anything apart from taking the money and running, and given that the legal profession seems to move slower than a dead sloth(apart from when its chasing an unpaid bill), it would take 5 yrs for any legal action to come to a conclusion

When the shell company implodes ...

alain williams

what then ? End users have kit that is vulnerable. OK: the importers are liable, what can they do ? The source code for these things will prolly not be in escrow so they cannot be patched, even if it was and if (big if) it is possible to patch & build a working image from the code - how do they get it on to end users' kit ? These things are often set up to get patches from the makers' machines - which are not longer there.

Should the importers be made to buy the kit back ? Even if this happens many end users will not want to due to the hassle involved.

This needs much more thought.

To teach is to learn twice.
-- Joseph Joubert