The Register Home Page

back to article UK lays down fresh legislation banning crummy default device passwords

Smart device manufacturers will have to play by new rules in the UK as of today, with laws coming into force to make it more difficult for cybercriminals to break into hardware such as phones and tablets. The Product Security and Telecommunications Infrastructure Act 2022 (PSTI Act) aims to enforce minimum security standards …

  1. Anonymous Coward
    Anonymous Coward

    Who knew. Bureaucrats serving multiple jurisdictions are more efficient than MORE bureaucrats serving just one. Or more likely too busy to serve anyone but themselves.

    1. UnknownUnknown

      “"UK IoT security laws will only require devices to meet three out of 13 standards from the European Telecommunications Standards Institute (ETSI)," said Callan.”

      More Brexit benefits.

      1. Anonymous Coward
        Anonymous Coward

        Was very much the point of my comment. The vote split certainly reflects a certain kind of voter amongst reg readers that bothered to click into the comments!

  2. Anonymous Coward
    Facepalm

    Default passwords are allowed?

    Can somebody explain this

    Default passwords are allowed, but if they're easily discoverable online, then it will fall foul of the Act.

    So the issue at the moment is I go and buy a router and it has a default password of "admin123". That's something that can be found online, possibly in the docs for the device. That manufacturer is still allowed a default, i.e. the same for everyone, password but it has to be something more secure than an obvious word and sequence of numbers?

    The problem isn't the strength of the password it's the fact that it's the same password used over and over. The idea of that never being published is farsical.

    The only way around this is if manufacturers have to use BOTH a strong password AND a different password per device. That leaves the issue of how they supply that to customers.

    Changing a weak password to a strong one isn't going to solve the real problem here.

    Call my cynical, but I doubt this will ever be enforced because the people who are involved in that don't even understand the issue.

    1. fPuck

      Re: Default passwords are allowed?

      According to the gov website it says: banning universal default and easily guessable passwords.

      To me that sounds like they're banning single passwords as well, the media have just blended the two.

      https://www.gov.uk/guidance/regulations-consumer-connectable-product-security

    2. Christoph

      Re: Default passwords are allowed?

      "That leaves the issue of how they supply that to customers."

      On one gadget I have the default password is the device serial number, which is on a label.

      1. heyrick Silver badge

        Re: Default passwords are allowed?

        Yup, I have two devices for which the instructions for the default recovery password [1] says "turn it upside down and read the last eight characters of the MAC address". Which seems to me to be a perfectly reasonable way to have a default address. Easy to discover if you're holding the device, but not liable to be found online.

        Certainly, I hope this will be the end of (unchangeable) username "admin", password "admin".

        1 - one of the devices says that recovering it in this way will, as a safety measure, erase all current configuration. They suggest that once the device has been set up, to export the settings to file in case they need to be restored.

        1. klh

          Re: Default passwords are allowed?

          The MAC address is publicly visible to anyone looking - and it also supplies you the manufacturer and maybe model to lookup how many digits and in which format to copy :)

          1. Yorick Hunt Silver badge

            Re: Default passwords are allowed?

            The MAC will be visible to anyone on the same network or (if the device has wireless connectivity) within radio range, and will identify the manufacturer of the network interface, not necessarily of the device itself.

            All* such "MAC is default password" devices I've encountered have only allowed that password to be used immediately after a factory reset, then insisted that you choose a new password.

            * All except for a handful of ISP-supplied modem/routers (I'm looking at you, Telstra!).

        2. vtcodger Silver badge

          Re: Default passwords are allowed?

          If unix is on any machine in the network, "arp-scan -l" from a terminal on that machine will list the IP address and Mac-address for everyone on the network. IIRC, the first 24 bits of the MAC address uniquely define the manufacturer and often the specific model. I imagine that means that future Unix malware will constantly scan infected networks and will try to assign its own password to any new device before users can get there.

          Not that I'm against using the MAC address for a password. I'm just suggesting that doing so may not be as secure as one might wish.

          1. tip pc Silver badge

            Re: Default passwords are allowed?

            If unix is on any machine in the network, "arp-scan -l" from a terminal on that machine will list the IP address and Mac-address for everyone on the network.

            that's only true for machines on that subnet, you won't see MAC's for machines on other subnets of that network.

            1. steviebuk Silver badge

              Re: Default passwords are allowed?

              If you target a specific AP, you'll get all the MACs of devices trying to connect to it.

        3. Blazde Silver badge

          Re: Default passwords are allowed?

          The legislation specifically outlaws passwords 'based on or derived from unique product identifiers, such as serial numbers', that would include MAC addresses.

          However this only applies 'when the product is not in the factory default state', so a first-use unique password of any kind (ie. admin/admin or MAC address derived) seems to be allowed as long as the product requires you to set your own password before doing any configuration. Depending how sensibly that's interpreted by the courts it leaves products which don't require configuration before use potentially wide open.

    3. that one in the corner Silver badge

      Re: Default passwords are allowed?

      > . That leaves the issue of how they supply that to customers.

      Hardly a massive problem to solve. They just need to be bothered to do it.

      The same way that some routers are supplied with a plastic card (and even a place to keep that card) wth the pre-set SSID and password for the WiFi. Or, if not considerate, a sticker at the back of the manual (put it somewhere convenient for you) or even, ick, a sticker on the bottom of the device.

      And the best manufacturers should provide a blank card or space on the sticker, with a note in bright colours that you can write your own choice of password in said blank and here is how to change it on the gadget. But that is getting into pipedream territory.

      Oh, and NOT using the device's serial number, or a trivial transform of it, for any part of the credentials!

      You should be able to tell people (e.g. help desk reps, people on advice forums who know that number is in the range where the gadget had such and such a quirk, ...) the SN without them then knowing immediately how to log into your widget.

      1. Cav

        Re: Default passwords are allowed?

        Default, serial number, passwords are not fixed passwords. As soon as you activate the device then you change the password. I've never had a device that I couldn't initially login to and change the password. Only then would you talk to support or online fora.

        1. that one in the corner Silver badge

          Re: Default passwords are allowed?

          > Default, serial number, passwords are not fixed passwords

          And many of the factory set, one code used everywhere, default passwords are not fixed either. Plenty are, but not all.

          And plenty of SN based one are fixed (especially ones based on MACs, presumably because the people who are too lazy to burn separate SN into a device are too lazy to consider security).

          > I've never had a device that I couldn't initially login to and change the password

          Two things:

          1. Lucky you

          2. But are you - or anyone here - the target for this?

          So you bought a device with an initial password set, you went in and changed it. Good. As you should.

          BUT that IMMEDIATELY takes you out of the group of people who leave the initial password; you know, all the people whose gadgets can be broken into using the factory set password.

          We *know* that group of people exist, or this would not be a discussion.

          And a factory set password based on the serial number is barely, if at all, stronger than setting them all to "MySecret12" or any other fixed value: both would be leaked to the Web and tada, the door is wide open.

          >

      2. Anonymous Coward
        Anonymous Coward

        Re: Default passwords are allowed?

        I'm not thrilled by the plastic card idea.

        I have a car with "keypad"* door unlock. There is a default unchangeable (maybe a dealer could change it?) number. With that number you can reset it to also include another number you chose, but you still have the default that the next owner can use. The manual said the number was on a card which of course was no longer with my used car.

        Online I found out it was also on a sticker under the dashboard. Well hidden so it was hard to get to. So you didn't have to worry about giving a ride to someone who could then break into your car.

        * unfortunately only five buttons with 2 digits on each.

        1. Anonymous Coward
          Anonymous Coward

          Re: Default passwords are allowed?

          I had a car with one of those. 5 buttons (each had 2 numbers, but it was really only one button), code was 5 buttons, so 3125 combinations. At 1 every 3 seconds, it would take about an hour and a half to try every single possible combination; on average, you'd hit the right combo in half that time. So not wonderfully secure, but not too bad.

          However, if you knew what one of the buttons was (probably either first or last), then it drops to 625, or 20 minutes of button-pushing to try every combo.

          It's probably possible to design a button sequence to test every combination with a fraction of the button pushes. For instance:

          123451234

          tests 12345, 23451, 34512, 45123, and 51234 in only 9 pushes instead of 20.

    4. katrinab Silver badge

      Re: Default passwords are allowed?

      I think what they mean is that it can have a default password out of the box, but it can't be same default password for all items in the SKU.

      Like for example with Wifi routers, previously the default password was something like "Netgear", now there is a card in the box with a password printed on it, and each one is different.

    5. Anonymous Coward
      Anonymous Coward

      Re: Default passwords are allowed?

      As you've pointed out @andy 123 although this law is well intentioned, it doesn't really make any sense or help the situation really as some routers from ISPs which are secured with passwords based on the MAC address of the router can still be gained gained if physical access to the router is still available (and the default password not changed) - but it is better than nothing I grant you

      1. Michael Wojcik

        Re: Default passwords are allowed?

        A MAC-based default password certainly does help the situation. Currently attackers can scan shodan.io for devices with known default passwords and stuff them in bulk from anywhere, looking for units that are still using the default. Having to be on the local network segment to get the MAC is an enormous improvement.

        The Mirai botnet and similar would never have gotten off the ground if all those devices had MAC-derived passwords.

    6. UnknownUnknown

      Re: Default passwords are allowed?

      The enforcement will be piss poor - look at the huffing and puffing around GDPR and the reality where someone like British Airways can be fined £190m reduced to £20m for an egregious breach.

    7. hoola Silver badge

      Re: Default passwords are allowed?

      I believe this is very simple. There is usually a serial number on the device so there is already a unique string that can be used as the password.

      Most new routers achieve this seemingly without difficulty.

      Why is it so difficult for all the other tat? The answer is cost & laziness.

      1. Michael Wojcik

        Re: Default passwords are allowed?

        Exactly. Security has been an externality for the manufacturers of Internet-of-Shit devices. Regulation, when it works, converts externalities into direct costs. That's the whole point of regulation.

        Once regulation makes it less expensive (to the manufacturers, or to the distributors, which becomes the same thing) to have unique default passwords on these things, they'll start having unique default passwords.

  3. Mike 137

    Actually, could do better

    "Default passwords are allowed, but if they're easily discoverable online, then it will fall foul of the Act"

    Yes another example of how little our legislators understand the technicalities of infosec. Unless each device has a unique default password (hardly practicable in the consumer device space), there's absolutely nothing to prevent a malicious actor buying a device and publishing the default password online. The only genuinely secure approach is for the device to be inoperative until a user password is entered (i.e. no default needed or allowed). This ain't hard to implement -- on every power up, the device checks whether a password has been created. If not, it requests one and and won't proceed with its main function until one is created.

    The other two quoted requirements (security contact point and declared support lifetime) are welcome as far as they go, but we really need a requirement to comply with secure development standards so devices are intrinsically more resistant to attack. Legislation to this end is apparently in progress in the US, but currently only for devices for government use. It's a pity that ,as usual, the UK refuses to be a real leader in this domain. We always seem to be satisfied with echoing minimum standards set by others.

    1. Catkin Silver badge

      Re: Actually, could do better

      I may be misunderstanding but I thought the default passwords on most home use routers were unique to each device.

      1. abend0c4 Silver badge

        Re: Actually, could do better

        Pretty much every network device is going to have a (uniquish) MAC address, pretty much every device has writable storage for updatable firmware (and is likely programmed in the factory) and anything that uses a password has to have somewhere writable to store the verification value, so unique defaults are perfectly doable. Passwords may not be ideal, but start with the easy wins...

        1. klh

          Re: Actually, could do better

          MAC addresses are also visible to anyone looking

          1. abend0c4 Silver badge

            Re: Actually, could do better

            Sorry, the point I was making (or trying to...) is that there already has to be a means of getting unique data into every device so that part of the problem is already solved. As you say, wireless networks leak MAC addresses (and the first half can be determined from the manufacturer) so they're not in themselves a solution. And nor are serial numbers...

          2. Michael Wojcik

            Re: Actually, could do better

            Threat-modeling failure. Anyone on the local subnet << anyone.

        2. vtcodger Silver badge

          Re: Actually, could do better

          As most anyone who has ever been near a manufacturing operation can tell you, the problem isn't setting a unique (or after allowing for the inevitable screwups) a near unique password on each device. One problem is telling the buyer/user exactly what their unique password is 100% of the time. Said user is going to be extremely displeased if they pay for a box then can't use it because they don't know that password. Another problem in many cases is how the vendor is supposed to authenticate over the air updates (Not that great in idea IMHO, but one which is popular at the moment) without a master password or some clue as to what the current password is.

          1. Michael Wojcik

            Re: Actually, could do better

            Said user is going to be extremely displeased if they pay for a box then can't use it because they don't know that password.

            That's why you mandate the unique password with regulation. Then displeased users have no choice, so there's no competitive advantage in not shipping with a unique password, and users are required to become a little more competent.

            And, frankly, user displeasure has done fuck-all to improve IoT crap, "smart" TVs, and the like, so if I were a manufacturer I wouldn't be worried about it in the slightest.

      2. Anonymous Coward
        Anonymous Coward

        Re: I may be misunderstanding...

        You must be young. Routers have gotten better. But in the old days I think I've had routers with default username/password like "admin/admin" or "admin/password".

      3. Ochib

        Re: Actually, could do better

        Nope, Virgin media use the default password of CHANGEME

    2. Innominate Chicken

      Re: Actually, could do better

      Not as hard as it sounds, randomly generate a password and set it as part of initialising the data/firmware on the device. Log the serial number and PW pairs, pass them to the packaging line and print them somewhere on the paperwork that comes with the device.

      All this needs is to be able to individually identify the devices at both stages, which one would hope is already tracked for traceability and QA purposes.

      1. Cav

        Re: Actually, could do better

        This is what happens now...

      2. Mike 137

        Re: Actually, could do better

        "Log the serial number and PW pairs, pass them to the packaging line and print them somewhere on the paperwork that comes with the device"

        Actually much more complicated to implement than requiring the user to create a password to unlock the device on first power up, and (for mass market devices) more likely to confuse non-technical users. We're not talking routers here that get set up by folks that understand at least something about the tech, but doorbells, dongles, security cameras and smart speakers. The reason the "default password" is typically e.g. '123456' is to avoid such confusion, which would be the more common the more 'random' the default was.

        Just for comparison, I created a power monitor a few years back, which required calibration for accuracy. I designed the code so that the first time it was powered up it was in calibration mode (for which there were detailed instructions provided). After calibration, it would power up in operational mode. This was a much more complex initialisation process for the user than merely being prompted to create a password, but it nevertheless worked fine.

    3. Cav

      Re: Actually, could do better

      Seriously? Default is not the same as generic. Most devices have unique passwords. They are set to a default value by the supplier and appear in the device documentation on on the packaging. Buy it, login and then change the password.

      Only the supplier would know the default password for a particular unique device.

      1. heyrick Silver badge

        Re: Actually, could do better

        "Only the supplier would know the default password for a particular unique device."

        Not necessarily. It's possible to extract data from the flash using the bootloader, split it out as what's the boot partition, unpack it, extract the password file, brute force it, and... tah dah, a functional password.

        I didn't do this, but somebody else did which is why I can log into my little media sharer device using the wide open telnet port (duh).

    4. Jason Bloomberg Silver badge
      Thumb Up

      Re: Actually, could do better

      Unless each device has a unique default password (hardly practicable in the consumer device space)

      An unguessable sequence of characters as that device's default is good enough. That is entirely practical, some have been doing that for years, and seems to be all the law is demanding.

      I am not as adverse to using default passwords based on a serial number as others are. That is as equally unguessable unless an attacker knows the serial number and how the password is derived from that..

      This is an attempt to trim the low-hung fruit, prevent manufacturers supplying low-hung fruit. I would agree the legislation could have gone further but it's a massive improvement on what we have allowed in the consumer market.

    5. Filippo Silver badge

      Re: Actually, could do better

      >nless each device has a unique default password (hardly practicable in the consumer device space)

      I don't think it's that difficult to ship each device with a strong unique default password (that is not just the MAC, or the S/N, or whatever). The routers I've got from my recent ISPs all did just that, and they aren't exactly top shelf stuff. How much can it possibly add to the device's cost? Pennies? A couple quid? Either way, it's money well spent if it means an attacker has to come to lazy user's house and read a physical sticker.

  4. elsergiovolador Silver badge
    Trollface

    List

    The legislator should just provide a list of secure default passwords for manufacturers to use /s

  5. Anonymous Coward
    Anonymous Coward

    Just so long as they don't publish the code I use on my luggage. Or my planetary air shield.

    1. chivo243 Silver badge
      1. John Robson Silver badge

        Just shows up as stars for me...

  6. Headley_Grange Silver badge

    How is this going to be enforceable for all that Chinese tat for sale online? The UK has no power to sue China-based sellers - they can't even make them pay VAT, FFS. It can tell Amazon, eBay, etc. to shut sellers down, but they'll just turn up a couple of hours later as a new company selling the same product with a different name. They can't go after the souks because, under current legislation, they aren't responsible for what they sell.

    1. Stu J

      Well they need to make the likes of Amazon, eBay etc responsible. A few fines and lawsuits might focus their minds a bit, and stop the influx of counterfeit/crap tech imports that claim to meet standards but clearly don't.

    2. Doctor Syntax Silver badge

      Have a few trading standards inspectors visit the warehouses and seize the entire stock of non-compliant devices. Watch the net container load sent straight back. Likewise intercept and check a sample of incoming packages and seize non-compliant goods, charge VAT/duty on the rest. That'll kill the straight from China route.

      1. Jason Bloomberg Silver badge

        Yes, exactly how they do it now for other prohibited, illegal, and non-compliant goods. Seizures and fines for retailers, importers, handlers, sellers, and manufacturers, will tackle most of it. Direct sales to consumers is harder but nothing they don't have to deal with already.

        Even if it doesn't remove the problem entirely it will greatly reduce it.

        1. Headley_Grange Silver badge

          Doesn't work. Which? did an article on dangerous heaters - all for sale on Amazon and eBay. All that happened was that Which told Amazon and eBay, got the stock answers and the products disappeared for a while before returning a few weeks later. No one got fined, prosecuted, ...., or anything really. They're probably still on sale and Bezos and the like are pocketing the profits without giving a fuck. Nothing will change.

        2. Headley_Grange Silver badge

          "but nothing they don't have to deal with already"

          Yes it is - it's a whole new other thing that's got to be looked for. I didn't see any announcement about the additional thousands of trading standards bodies to support this.

          I think it'd be better to offer a bounty for finding non-complying products (not just for passwords, safety as well) to be paid for by fines on the retailer (Amazon, Facebook, etc.) large enough to make it worthwhile - say £20k per confirmed find. There'd be no need for additional trading standards staff and it would be better than wandering round a muddy field at night with a metal detector.

          1. Killfalcon

            20k? At that point, you'd be able to make money importing non-compliant stuff, putting on a different hat, then reporting your yourself for the bounty! :D

      2. Androgynous Cupboard Silver badge

        Rishi's thought of that one too. Store them all in a freeport (like, say, the one in Tees Valley that Baron Greenback Houchen (Con) bought for a handful of magic beans), and I'd presume they're not required to meet UK standards until they're fully brought into the UK.

      3. phuzz Silver badge

        The slight drawback to this is that over five million containers reach the UK each year, that's about 13,000 per day, which would make it somewhat impractical to search even a small fraction of them.

    3. Anonymous Coward
      Anonymous Coward

      "chinese tat"

      Bearing in mind the regulators are utterly powerless and incapable of making sure imported "chinese tat" even complies with basic electrical, fire safety or emc standards then this seems act just seems a waste of ram and electrons. A seemingly good idea, but utterly unenforceable.

      1. UnknownUnknown

        Re: "chinese tat"

        It’s more new legislation whilst previous remains almost completely enforced.

        - electrical safety

        - mobile phones/driving

        - driving like a wanker

        I was heartened to see looks like the Office for Electrical Tat looks like it was setup anew and is based in Birmingham, with only a small Londonshire Office.

        Like wow !! Levelling Up! In action.

      2. hoola Silver badge

        Re: "chinese tat"

        I think it is even more basic.

        Whilst people continue to buy & setup all this shite without a care in the world because it enables them to see who is at the door, switch the oven on, view the dog or power up a vibrator nothing will change.

        Huge numbers of people are addicted to this crap because it is seen as cool. I simply don't give a toss if I can see who is at the door when I am out or know what the temperature of the fridge is on an app. If it is any of the crap delivery people they just leave it on the doorstep anyway. Having a recording of them doing it is worthless. The delivery company already knows they have done it as most is "photo on delivery".

        A friend was proudly showing me some app on his phone for his solar panels and battery with funky diagrams etc. The bit that made me chuckle is he lectures in cyber security at a university.

  7. Stu J

    A good start...

    ...but companies should also be mandated to provide perpetual local control of all devices.

    Being reliant on a cloud service that could shut down (or ramp up subscription costs) tomorrow on the whim of a company (or whoever decides to buy them) is not a good position for consumers to be in.

    It doesn't even have to be a "both" - even making firmware available that provides the ability to read data from and send instructions to the device locally, and allowing users to load that firmware if they don't want to be locked in to a cloud model would be better than the status quo.

    I've nothing against manufacturers paywalling more intelligent functionality, storage etc behind a subscription, but the raw device capabilities should be accessible and documented if the consumer requires it and wants to roll their own integrations.

    1. heyrick Silver badge
      Pint

      Re: A good start...

      Dammit, can't upvote this enough.

    2. devin3782
      Pint

      Re: A good start...

      Yes! this! have more up votes, this is essential.

  8. steviebuk Silver badge

    Never going to happen

    China ignores all world laws so all the Chinese shit off Amazon will still have default, easy to guess passwords.

  9. frankyunderwood123 Silver badge

    Not enforceable

    There's no way this is going to be able to be enforced.

    Sure, the big brands will play along, but there's hundreds of manufacturers, most in Asia - China - just flooding the market with products.

    Some cheap and nasty, others cheap and not that bad.

    To enforce this, means getting Amazon to enforce the new laws on sellers.

    Given Amazon barely even pay tax and get away with it, good luck getting them involved.

    Also, AliExpress continues to gain popularity in the UK - despite slow shipping times and often exceptionally questionable goods - the crazy low prices attract people.

    We're no longer in a world of Curry's or Maplin (no longer exist) or Argos dominance of tech products - that ended well over a decade back.

    We're in a world where you can get product shipped from anywhere on the planet.

  10. Version 1.0
    Thumb Up

    Create 100% reliable passwords.

    OK so you can record and write down your password e.g "Admin123" but just remember that's only a hint because the fully functional and safe password would be "Gweinyddol123" - just never create passwords in English because that's the worlds most common language researched by hackers. Even if they are using AI then it's a bet that hidden Welsh will never be hacked. I've started using Welsh passwords since the early days, just planning (and 100% successful) never to get hacked.

    1. steviebuk Silver badge

      Re: Create 100% reliable passwords.

      Had one lady at work write her password on the noticeboard in her office. I smirked a bit as she said "No one can read it, I'm the only one left in the building that can read and write shorthand". And she's right. At the new place I mentioned this story to a new starter to only be asked "What's shorthand?". I felt old.

      1. John Robson Silver badge

        Re: Create 100% reliable passwords.

        Humans are rather good at looking after small bits of paper.

        And at the point where someone has physical access to a machine, it's probably game over anyway.

  11. chivo243 Silver badge
    Facepalm

    Misguided

    Really, all this over 'default' passwords that are supposed to be changed at config time?? If you can't follow instructions, put your hands in your pockets, and please step away from the device, call your kid to assist...

  12. IGotOut Silver badge

    Oh no...

    TheHappyLuckyGoSunnyCompany will get fined.

    Never mind

    TheSunnyLuckyGoHappyCompany has an almost identical product, and it's STILL 1/3 price of the well know brands.

    1. Headley_Grange Silver badge

      Re: Oh no...

      Made me laugh. Absolute gurarantee of Chinese Tat Store on eBay is having "lucky" in the name. Even if I've filtered for "UK Only" they still crop up, presumably because they have a warehouse in hte UK.

      1. Yet Another Anonymous coward Silver badge

        Re: Oh no...

        Lucky Goldstar (LG) has annual sales of $65Bn

        But I assume you but your TVs from the English Electric Valve company

        1. Headley_Grange Silver badge

          Re: Oh no...

          I couldn't find the Lucky Goldstar eBay store - could you send me a link so I can block it.

  13. Tom Paine

    * makes a note in 2029 calendar to heck back on how effectively this is enforced and what sort of sanctions follow (including crapware flogged on Amazon, eBay etc)

    Can't see it, myself.

  14. greenwood-IT

    A far simpler option would be to allow a default password but insist on it being changed on first use.

    The main advantage would be that you can then easily gain access following a Factory Reset. The idea of resetting a device and THEN having to find a sticky label for the password :-(

    The idea of a "Security Support Contact" and a published "Best Before" date would be handy, but I bet a bunch of the cheap IoT companies would just go bust and rebrand (if they have a brand!) every year.

    1. Zola

      A "default" password IS permitted after a factory reset, which must then be reset by the user.

      An even easier solution is for there to be NO PASSWORD after a factory reset, and the user has to set a password on first login.

      There's simply no need for a "default" password at all once the device has been factory reset. In fact, having a "default" (and likely well known) password is what got us into this mess in the first place.

  15. Erlang Lacod

    Caveat emptor. If users cannot be bothered to protect themselves why should we care. It is up to them and the industry should not intervene. Apparently ignorance is bliss so they get the result they deserve,

    1. Killfalcon

      If only those devices weren't connected to the internet, I might agree, but they are.

      These insecure devices allow viruses to spread, and botnets to grow. Ultimately it's to everyone's benefits to have fewer insecure devices around.

    2. unimaginative Bronze badge

      Why does may car need an MOT? If I do not check it without it being a legal requirement I will get what I deserve, right?

  16. Grogan

    How is someone supposed to recover a device from corrupted settings when they most likely won't know the original password of the device, after a reset? Yeah sure, they kept the piece of paper /s

    I would simply tell people to throw the devices away and buy new ones, because my time is too expensive to waste on that. How would manufacturer's tech support even help you unless there's a backdoor or another "default" password that can be discovered and publicized?

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like