News: 1714391109

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UK lays down fresh legislation banning crummy default device passwords

(2024/04/29)


Smart device manufacturers will have to play by new rules in the UK as of today, with laws coming into force to make it more difficult for cybercriminals to break into hardware such as phones and tablets.

The Product Security and Telecommunications Infrastructure Act 2022 ( [1]PSTI Act ) aims to enforce minimum security standards by which all device manufacturers must abide.

Of the three main requirements all smart devices must adhere to, shipping devices with easily crackable default passwords is arguably the headliner. Default passwords are allowed, but if they're easily discoverable online, then it will fall foul of the Act.

[2]

It has been coming for a while. We started reporting on the proposed PSTI Act back in 2021 and even at the bill's first inception, it primarily aimed to stamp out these what's-even-the-point passwords.

[3]

[4]

It's almost certainly a good idea – especially when we have cheap overseas kit coming in allowing pretty much anyone to [5]break into devices like child trackers with passwords such as "12345."

Professor Alan Woodward, a computer scientist at the University of Surrey in England who specializes in security, told The Register : "I think it's a great first step. Certainly better than the vacuum that we had previously. It focuses on the basics, and one might think that's a missed opportunity, but the vast majority of successful attacks are still simple hygiene factors such as weak passwords.

[6]

"As with all these things it could go further, and it would be nice to think this is a first step rather than a completed journey."

The newly instated PSTI Act also compels manufacturers to provide a point of contact for individuals reporting security concerns, and they must also make clear the minimum period for which the device will receive security updates.

There are no specific rules that stipulate what that minimum length of time should be, but whatever the product's lifespan is, it must be clearly communicated to customers.

[7]

The PSTI Act applies to any consumer smart device that either connects directly to the internet or to a home network. Such devices include:

Entertainment devices: [8]Smart TV , streaming devices, smart speakers, games consoles, smartphones, and tablets with cellular connectivity

Home surveillance: Video [9]doorbells , home [10]security cameras , and baby monitors

Home appliances: Light bulbs, plugs, ovens, fridges, washing machines, thermostats, kettles

Wearables such as fitness trackers and smart watches

To coincide with the PSTI Act's introduction, the UK's National Cyber Security Centre (NCSC) issued a [11]leaflet [PDF] for people who want to bolster their device's security, complete with its longstanding guidance to create [12]passwords using three random words .

While the legislation has been welcomed widely as an important and necessary first step, experts have highlighted some key concerns. Tim Callan, chief experience officer at Sectigo, said the laws don't go far enough and lag behind the recommended standards in Europe.

"UK IoT security laws will only require devices to meet three out of 13 standards from the European Telecommunications Standards Institute (ETSI)," said Callan.

"That still leaves a major gap in our defenses for hackers to infiltrate our smart devices. If the UK wants to get truly serious about securing our devices, they must push businesses to do more."

The Office for Product Safety and Standards (OPSS) has been tasked with enforcing the new rules on vendors, which makes a lot of sense given that it was already responsible for the UK's existing product safety regulations.

Others, however, remain skeptical about how hard the UK government will come down on offending vendors. Not complying with the PSTI Act is a criminal offense for domestic and overseas manufacturers, with the official punishment being a £10 million ($12.5 million) fine or 4 percent of qualifying worldwide revenue (whichever is higher).

[13]185K people's sensitive data in the pits after ransomware raid on Cherry Health

[14]Roku makes 2FA mandatory for all after nearly 600K accounts pwned

[15]D-Link issues rip and replace order for besieged NAS drives

[16]Vans claims cyber crooks didn't run off with its customers' financial info

Woodward said: "My big concern is whether or not the government will enforce it. The new law has the ability to fine vendors significant amounts, and that makes commercial operations take note. However, only if they know it's a real threat. Time will tell but I really hope the government uses the power of this law to crack down on poor practice, particularly from vendors where they build to a price point and security is an afterthought.

"It's noteworthy that it has taken a long time to get to this point. Many in the sector have been advocating strongly for such measures for years, so part of me thinks it's about time." ®

Get our [17]Tech Resources



[1] https://www.legislation.gov.uk/ukpga/2022/46/contents/enacted

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zi-EHnJasP6FCRLduL6S9gAAABA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zi-EHnJasP6FCRLduL6S9gAAABA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zi-EHnJasP6FCRLduL6S9gAAABA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2019/09/05/pwning_gps_trackers/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zi-EHnJasP6FCRLduL6S9gAAABA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zi-EHnJasP6FCRLduL6S9gAAABA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2024/04/09/lg_tv_critical_bugs/

[9] https://www.theregister.com/2024/01/25/amazon_ring_sounds_death_knell/

[10] https://www.theregister.com/2024/03/11/airbnb_bans_indoor_security_cameras/

[11] https://www.ncsc.gov.uk/files/Security-law-smart-devices-NCSC.pdf

[12] https://www.theregister.com/2021/04/09/ncsc_secure_passwords_three_words_advice/

[13] https://www.theregister.com/2024/04/18/ransomware_cherry_health/

[14] https://www.theregister.com/2024/04/15/roku_2fa_for_everyone/

[15] https://www.theregister.com/2024/04/09/dlink_issues_rip_and_replace/

[16] https://www.theregister.com/2024/03/24/vans_breach_disclosure/

[17] https://whitepapers.theregister.com/



Binraider

Who knew. Bureaucrats serving multiple jurisdictions are more efficient than MORE bureaucrats serving just one. Or more likely too busy to serve anyone but themselves.

Default passwords are allowed?

andy 103

Can somebody explain this

Default passwords are allowed, but if they're easily discoverable online, then it will fall foul of the Act.

So the issue at the moment is I go and buy a router and it has a default password of "admin123". That's something that can be found online, possibly in the docs for the device. That manufacturer is still allowed a default, i.e. the same for everyone, password but it has to be something more secure than an obvious word and sequence of numbers?

The problem isn't the strength of the password it's the fact that it's the same password used over and over. The idea of that never being published is farsical.

The only way around this is if manufacturers have to use BOTH a strong password AND a different password per device. That leaves the issue of how they supply that to customers.

Changing a weak password to a strong one isn't going to solve the real problem here.

Call my cynical, but I doubt this will ever be enforced because the people who are involved in that don't even understand the issue.

Re: Default passwords are allowed?

fPuck

According to the gov website it says: banning universal default and easily guessable passwords.

To me that sounds like they're banning single passwords as well, the media have just blended the two.

https://www.gov.uk/guidance/regulations-consumer-connectable-product-security

Re: Default passwords are allowed?

Christoph

" That leaves the issue of how they supply that to customers. "

On one gadget I have the default password is the device serial number, which is on a label.

Re: Default passwords are allowed?

heyrick

Yup, I have two devices for which the instructions for the default recovery password [1] says "turn it upside down and read the last eight characters of the MAC address". Which seems to me to be a perfectly reasonable way to have a default address. Easy to discover if you're holding the device, but not liable to be found online.

Certainly, I hope this will be the end of (unchangeable) username "admin", password "admin".

1 - one of the devices says that recovering it in this way will, as a safety measure, erase all current configuration. They suggest that once the device has been set up, to export the settings to file in case they need to be restored.

Re: Default passwords are allowed?

klh

The MAC address is publicly visible to anyone looking - and it also supplies you the manufacturer and maybe model to lookup how many digits and in which format to copy :)

Re: Default passwords are allowed?

Yorick Hunt

The MAC will be visible to anyone on the same network or (if the device has wireless connectivity) within radio range, and will identify the manufacturer of the network interface, not necessarily of the device itself.

All* such "MAC is default password" devices I've encountered have only allowed that password to be used immediately after a factory reset, then insisted that you choose a new password.

* All except for a handful of ISP-supplied modem/routers (I'm looking at you, Telstra!).

Re: Default passwords are allowed?

vtcodger

If unix is on any machine in the network, "arp-scan -l" from a terminal on that machine will list the IP address and Mac-address for everyone on the network. IIRC, the first 24 bits of the MAC address uniquely define the manufacturer and often the specific model. I imagine that means that future Unix malware will constantly scan infected networks and will try to assign its own password to any new device before users can get there.

Not that I'm against using the MAC address for a password. I'm just suggesting that doing so may not be as secure as one might wish.

Re: Default passwords are allowed?

that one in the corner

> . That leaves the issue of how they supply that to customers.

Hardly a massive problem to solve. They just need to be bothered to do it.

The same way that some routers are supplied with a plastic card (and even a place to keep that card) wth the pre-set SSID and password for the WiFi. Or, if not considerate, a sticker at the back of the manual (put it somewhere convenient for you) or even, ick, a sticker on the bottom of the device.

And the best manufacturers should provide a blank card or space on the sticker, with a note in bright colours that you can write your own choice of password in said blank and here is how to change it on the gadget. But that is getting into pipedream territory.

Oh, and NOT using the device's serial number, or a trivial transform of it, for any part of the credentials!

You should be able to tell people (e.g. help desk reps, people on advice forums who know that number is in the range where the gadget had such and such a quirk, ...) the SN without them then knowing immediately how to log into your widget.

Re: Default passwords are allowed?

Cav

Default, serial number, passwords are not fixed passwords. As soon as you activate the device then you change the password. I've never had a device that I couldn't initially login to and change the password. Only then would you talk to support or online fora.

Re: Default passwords are allowed?

Anonymous Coward

I'm not thrilled by the plastic card idea.

I have a car with "keypad"* door unlock. There is a default unchangeable (maybe a dealer could change it?) number. With that number you can reset it to also include another number you chose, but you still have the default that the next owner can use. The manual said the number was on a card which of course was no longer with my used car.

Online I found out it was also on a sticker under the dashboard. Well hidden so it was hard to get to. So you didn't have to worry about giving a ride to someone who could then break into your car.

* unfortunately only five buttons with 2 digits on each.

Re: Default passwords are allowed?

katrinab

I think what they mean is that it can have a default password out of the box, but it can't be same default password for all items in the SKU.

Like for example with Wifi routers, previously the default password was something like "Netgear", now there is a card in the box with a password printed on it, and each one is different.

Actually, could do better

Mike 137

" Default passwords are allowed, but if they're easily discoverable online, then it will fall foul of the Act "

Yes another example of how little our legislators understand the technicalities of infosec. Unless each device has a unique default password (hardly practicable in the consumer device space), there's absolutely nothing to prevent a malicious actor buying a device and publishing the default password online. The only genuinely secure approach is for the device to be inoperative until a user password is entered (i.e. no default needed or allowed). This ain't hard to implement -- on every power up, the device checks whether a password has been created. If not, it requests one and and won't proceed with its main function until one is created.

The other two quoted requirements (security contact point and declared support lifetime) are welcome as far as they go, but we really need a requirement to comply with secure development standards so devices are intrinsically more resistant to attack. Legislation to this end is apparently in progress in the US, but currently only for devices for government use. It's a pity that ,as usual, the UK refuses to be a real leader in this domain. We always seem to be satisfied with echoing minimum standards set by others.

Re: Actually, could do better

Catkin

I may be misunderstanding but I thought the default passwords on most home use routers were unique to each device.

Re: Actually, could do better

abend0c4

Pretty much every network device is going to have a (uniquish) MAC address, pretty much every device has writable storage for updatable firmware (and is likely programmed in the factory) and anything that uses a password has to have somewhere writable to store the verification value, so unique defaults are perfectly doable. Passwords may not be ideal, but start with the easy wins...

Re: Actually, could do better

klh

MAC addresses are also visible to anyone looking

Re: Actually, could do better

abend0c4

Sorry, the point I was making (or trying to...) is that there already has to be a means of getting unique data into every device so that part of the problem is already solved. As you say, wireless networks leak MAC addresses (and the first half can be determined from the manufacturer) so they're not in themselves a solution. And nor are serial numbers...

Re: I may be misunderstanding...

Anonymous Coward

You must be young. Routers have gotten better. But in the old days I think I've had routers with default username/password like "admin/admin" or "admin/password".

Re: Actually, could do better

Innominate Chicken

Not as hard as it sounds, randomly generate a password and set it as part of initialising the data/firmware on the device. Log the serial number and PW pairs, pass them to the packaging line and print them somewhere on the paperwork that comes with the device.

All this needs is to be able to individually identify the devices at both stages, which one would hope is already tracked for traceability and QA purposes.

Re: Actually, could do better

Cav

This is what happens now...

Re: Actually, could do better

Mike 137

" Log the serial number and PW pairs, pass them to the packaging line and print them somewhere on the paperwork that comes with the device "

Actually much more complicated to implement than requiring the user to create a password to unlock the device on first power up, and (for mass market devices) more likely to confuse non-technical users. We're not talking routers here that get set up by folks that understand at least something about the tech, but doorbells, dongles, security cameras and smart speakers. The reason the "default password" is typically e.g. '123456' is to avoid such confusion, which would be the more common the more 'random' the default was.

Just for comparison, I created a power monitor a few years back, which required calibration for accuracy. I designed the code so that the first time it was powered up it was in calibration mode (for which there were detailed instructions provided). After calibration, it would power up in operational mode. This was a much more complex initialisation process for the user than merely being prompted to create a password, but it nevertheless worked fine.

Re: Actually, could do better

Cav

Seriously? Default is not the same as generic. Most devices have unique passwords. They are set to a default value by the supplier and appear in the device documentation on on the packaging. Buy it, login and then change the password.

Only the supplier would know the default password for a particular unique device.

Re: Actually, could do better

heyrick

" Only the supplier would know the default password for a particular unique device. "

Not necessarily. It's possible to extract data from the flash using the bootloader, split it out as what's the boot partition, unpack it, extract the password file, brute force it, and... tah dah, a functional password.

I didn't do this, but somebody else did which is why I can log into my little media sharer device using the wide open telnet port (duh).

Re: Actually, could do better

Jason Bloomberg

Unless each device has a unique default password (hardly practicable in the consumer device space)

An unguessable sequence of characters as that device's default is good enough. That is entirely practical, some have been doing that for years, and seems to be all the law is demanding.

I am not as adverse to using default passwords based on a serial number as others are. That is as equally unguessable unless an attacker knows the serial number and how the password is derived from that..

This is an attempt to trim the low-hung fruit, prevent manufacturers supplying low-hung fruit. I would agree the legislation could have gone further but it's a massive improvement on what we have allowed in the consumer market.

List

elsergiovolador

The legislator should just provide a list of secure default passwords for manufacturers to use /s

Anonymous Coward

Just so long as they don't publish the code I use on my luggage. Or my planetary air shield.

Headley_Grange

How is this going to be enforceable for all that Chinese tat for sale online? The UK has no power to sue China-based sellers - they can't even make them pay VAT, FFS. It can tell Amazon, eBay, etc. to shut sellers down, but they'll just turn up a couple of hours later as a new company selling the same product with a different name. They can't go after the souks because, under current legislation, they aren't responsible for what they sell.

Stu J

Well they need to make the likes of Amazon, eBay etc responsible. A few fines and lawsuits might focus their minds a bit, and stop the influx of counterfeit/crap tech imports that claim to meet standards but clearly don't.

Doctor Syntax

Have a few trading standards inspectors visit the warehouses and seize the entire stock of non-compliant devices. Watch the net container load sent straight back. Likewise intercept and check a sample of incoming packages and seize non-compliant goods, charge VAT/duty on the rest. That'll kill the straight from China route.

Jason Bloomberg

Yes, exactly how they do it now for other prohibited, illegal, and non-compliant goods. Seizures and fines for retailers, importers, handlers, sellers, and manufacturers, will tackle most of it. Direct sales to consumers is harder but nothing they don't have to deal with already.

Even if it doesn't remove the problem entirely it will greatly reduce it.

Headley_Grange

Doesn't work. Which? did an article on dangerous heaters - all for sale on Amazon and eBay. All that happened was that Which told Amazon and eBay, got the stock answers and the products disappeared for a while before returning a few weeks later. No one got fined, prosecuted, ...., or anything really. They're probably still on sale and Bezos and the like are pocketing the profits without giving a fuck. Nothing will change.

Headley_Grange

"but nothing they don't have to deal with already"

Yes it is - it's a whole new other thing that's got to be looked for. I didn't see any announcement about the additional thousands of trading standards bodies to support this.

I think it'd be better to offer a bounty for finding non-complying products (not just for passwords, safety as well) to be paid for by fines on the retailer (Amazon, Facebook, etc.) large enough to make it worthwhile - say £20k per confirmed find. There'd be no need for additional trading standards staff and it would be better than wandering round a muddy field at night with a metal detector.

Androgynous Cupboard

Rishi's thought of that one too. Store them all in a freeport (like, say, the one in Tees Valley that Baron Greenback Houchen (Con) bought for a handful of magic beans), and I'd presume they're not required to meet UK standards until they're fully brought into the UK.

phuzz

The slight drawback to this is that over five million containers reach the UK each year, that's about 13,000 per day, which would make it somewhat impractical to search even a small fraction of them.

A good start...

Stu J

...but companies should also be mandated to provide perpetual local control of all devices.

Being reliant on a cloud service that could shut down (or ramp up subscription costs) tomorrow on the whim of a company (or whoever decides to buy them) is not a good position for consumers to be in.

It doesn't even have to be a "both" - even making firmware available that provides the ability to read data from and send instructions to the device locally, and allowing users to load that firmware if they don't want to be locked in to a cloud model would be better than the status quo.

I've nothing against manufacturers paywalling more intelligent functionality, storage etc behind a subscription, but the raw device capabilities should be accessible and documented if the consumer requires it and wants to roll their own integrations.

Re: A good start...

heyrick

Dammit, can't upvote this enough.

Never going to happen

steviebuk

China ignores all world laws so all the Chinese shit off Amazon will still have default, easy to guess passwords.

Not enforceable

frankyunderwood123

There's no way this is going to be able to be enforced.

Sure, the big brands will play along, but there's hundreds of manufacturers, most in Asia - China - just flooding the market with products.

Some cheap and nasty, others cheap and not that bad.

To enforce this, means getting Amazon to enforce the new laws on sellers.

Given Amazon barely even pay tax and get away with it, good luck getting them involved.

Also, AliExpress continues to gain popularity in the UK - despite slow shipping times and often exceptionally questionable goods - the crazy low prices attract people.

We're no longer in a world of Curry's or Maplin (no longer exist) or Argos dominance of tech products - that ended well over a decade back.

We're in a world where you can get product shipped from anywhere on the planet.

Bing's Rule:
Don't try to stem the tide -- move the beach.