Who knew. Bureaucrats serving multiple jurisdictions are more efficient than MORE bureaucrats serving just one. Or more likely too busy to serve anyone but themselves.
UK lays down fresh legislation banning crummy default device passwords
Smart device manufacturers will have to play by new rules in the UK as of today, with laws coming into force to make it more difficult for cybercriminals to break into hardware such as phones and tablets. The Product Security and Telecommunications Infrastructure Act 2022 (PSTI Act) aims to enforce minimum security standards …
COMMENTS
-
Monday 29th April 2024 12:17 GMT Anonymous Coward
Default passwords are allowed?
Can somebody explain this
Default passwords are allowed, but if they're easily discoverable online, then it will fall foul of the Act.
So the issue at the moment is I go and buy a router and it has a default password of "admin123". That's something that can be found online, possibly in the docs for the device. That manufacturer is still allowed a default, i.e. the same for everyone, password but it has to be something more secure than an obvious word and sequence of numbers?
The problem isn't the strength of the password it's the fact that it's the same password used over and over. The idea of that never being published is farsical.
The only way around this is if manufacturers have to use BOTH a strong password AND a different password per device. That leaves the issue of how they supply that to customers.
Changing a weak password to a strong one isn't going to solve the real problem here.
Call my cynical, but I doubt this will ever be enforced because the people who are involved in that don't even understand the issue.
-
Monday 29th April 2024 12:20 GMT fPuck
Re: Default passwords are allowed?
According to the gov website it says: banning universal default and easily guessable passwords.
To me that sounds like they're banning single passwords as well, the media have just blended the two.
https://www.gov.uk/guidance/regulations-consumer-connectable-product-security
-
-
Monday 29th April 2024 13:39 GMT heyrick
Re: Default passwords are allowed?
Yup, I have two devices for which the instructions for the default recovery password [1] says "turn it upside down and read the last eight characters of the MAC address". Which seems to me to be a perfectly reasonable way to have a default address. Easy to discover if you're holding the device, but not liable to be found online.
Certainly, I hope this will be the end of (unchangeable) username "admin", password "admin".
1 - one of the devices says that recovering it in this way will, as a safety measure, erase all current configuration. They suggest that once the device has been set up, to export the settings to file in case they need to be restored.
-
-
Monday 29th April 2024 14:38 GMT Yorick Hunt
Re: Default passwords are allowed?
The MAC will be visible to anyone on the same network or (if the device has wireless connectivity) within radio range, and will identify the manufacturer of the network interface, not necessarily of the device itself.
All* such "MAC is default password" devices I've encountered have only allowed that password to be used immediately after a factory reset, then insisted that you choose a new password.
* All except for a handful of ISP-supplied modem/routers (I'm looking at you, Telstra!).
-
-
Monday 29th April 2024 15:49 GMT vtcodger
Re: Default passwords are allowed?
If unix is on any machine in the network, "arp-scan -l" from a terminal on that machine will list the IP address and Mac-address for everyone on the network. IIRC, the first 24 bits of the MAC address uniquely define the manufacturer and often the specific model. I imagine that means that future Unix malware will constantly scan infected networks and will try to assign its own password to any new device before users can get there.
Not that I'm against using the MAC address for a password. I'm just suggesting that doing so may not be as secure as one might wish.
-
Tuesday 30th April 2024 12:30 GMT tip pc
Re: Default passwords are allowed?
If unix is on any machine in the network, "arp-scan -l" from a terminal on that machine will list the IP address and Mac-address for everyone on the network.
that's only true for machines on that subnet, you won't see MAC's for machines on other subnets of that network.
-
-
Monday 29th April 2024 16:03 GMT Blazde
Re: Default passwords are allowed?
The legislation specifically outlaws passwords 'based on or derived from unique product identifiers, such as serial numbers', that would include MAC addresses.
However this only applies 'when the product is not in the factory default state', so a first-use unique password of any kind (ie. admin/admin or MAC address derived) seems to be allowed as long as the product requires you to set your own password before doing any configuration. Depending how sensibly that's interpreted by the courts it leaves products which don't require configuration before use potentially wide open.
-
-
-
Monday 29th April 2024 12:39 GMT that one in the corner
Re: Default passwords are allowed?
> . That leaves the issue of how they supply that to customers.
Hardly a massive problem to solve. They just need to be bothered to do it.
The same way that some routers are supplied with a plastic card (and even a place to keep that card) wth the pre-set SSID and password for the WiFi. Or, if not considerate, a sticker at the back of the manual (put it somewhere convenient for you) or even, ick, a sticker on the bottom of the device.
And the best manufacturers should provide a blank card or space on the sticker, with a note in bright colours that you can write your own choice of password in said blank and here is how to change it on the gadget. But that is getting into pipedream territory.
Oh, and NOT using the device's serial number, or a trivial transform of it, for any part of the credentials!
You should be able to tell people (e.g. help desk reps, people on advice forums who know that number is in the range where the gadget had such and such a quirk, ...) the SN without them then knowing immediately how to log into your widget.
-
Monday 29th April 2024 13:23 GMT Cav
Re: Default passwords are allowed?
Default, serial number, passwords are not fixed passwords. As soon as you activate the device then you change the password. I've never had a device that I couldn't initially login to and change the password. Only then would you talk to support or online fora.
-
Monday 29th April 2024 17:28 GMT that one in the corner
Re: Default passwords are allowed?
> Default, serial number, passwords are not fixed passwords
And many of the factory set, one code used everywhere, default passwords are not fixed either. Plenty are, but not all.
And plenty of SN based one are fixed (especially ones based on MACs, presumably because the people who are too lazy to burn separate SN into a device are too lazy to consider security).
> I've never had a device that I couldn't initially login to and change the password
Two things:
1. Lucky you
2. But are you - or anyone here - the target for this?
So you bought a device with an initial password set, you went in and changed it. Good. As you should.
BUT that IMMEDIATELY takes you out of the group of people who leave the initial password; you know, all the people whose gadgets can be broken into using the factory set password.
We *know* that group of people exist, or this would not be a discussion.
And a factory set password based on the serial number is barely, if at all, stronger than setting them all to "MySecret12" or any other fixed value: both would be leaked to the Web and tada, the door is wide open.
>
-
-
Monday 29th April 2024 15:12 GMT Anonymous Coward
Re: Default passwords are allowed?
I'm not thrilled by the plastic card idea.
I have a car with "keypad"* door unlock. There is a default unchangeable (maybe a dealer could change it?) number. With that number you can reset it to also include another number you chose, but you still have the default that the next owner can use. The manual said the number was on a card which of course was no longer with my used car.
Online I found out it was also on a sticker under the dashboard. Well hidden so it was hard to get to. So you didn't have to worry about giving a ride to someone who could then break into your car.
* unfortunately only five buttons with 2 digits on each.
-
Wednesday 1st May 2024 14:46 GMT Anonymous Coward
Re: Default passwords are allowed?
I had a car with one of those. 5 buttons (each had 2 numbers, but it was really only one button), code was 5 buttons, so 3125 combinations. At 1 every 3 seconds, it would take about an hour and a half to try every single possible combination; on average, you'd hit the right combo in half that time. So not wonderfully secure, but not too bad.
However, if you knew what one of the buttons was (probably either first or last), then it drops to 625, or 20 minutes of button-pushing to try every combo.
It's probably possible to design a button sequence to test every combination with a fraction of the button pushes. For instance:
123451234
tests 12345, 23451, 34512, 45123, and 51234 in only 9 pushes instead of 20.
-
-
-
Monday 29th April 2024 15:39 GMT katrinab
Re: Default passwords are allowed?
I think what they mean is that it can have a default password out of the box, but it can't be same default password for all items in the SKU.
Like for example with Wifi routers, previously the default password was something like "Netgear", now there is a card in the box with a password printed on it, and each one is different.
-
Monday 29th April 2024 21:46 GMT Anonymous Coward
Re: Default passwords are allowed?
As you've pointed out @andy 123 although this law is well intentioned, it doesn't really make any sense or help the situation really as some routers from ISPs which are secured with passwords based on the MAC address of the router can still be gained gained if physical access to the router is still available (and the default password not changed) - but it is better than nothing I grant you
-
Tuesday 30th April 2024 15:59 GMT Michael Wojcik
Re: Default passwords are allowed?
A MAC-based default password certainly does help the situation. Currently attackers can scan shodan.io for devices with known default passwords and stuff them in bulk from anywhere, looking for units that are still using the default. Having to be on the local network segment to get the MAC is an enormous improvement.
The Mirai botnet and similar would never have gotten off the ground if all those devices had MAC-derived passwords.
-
-
Tuesday 30th April 2024 08:35 GMT hoola
Re: Default passwords are allowed?
I believe this is very simple. There is usually a serial number on the device so there is already a unique string that can be used as the password.
Most new routers achieve this seemingly without difficulty.
Why is it so difficult for all the other tat? The answer is cost & laziness.
-
Tuesday 30th April 2024 16:01 GMT Michael Wojcik
Re: Default passwords are allowed?
Exactly. Security has been an externality for the manufacturers of Internet-of-Shit devices. Regulation, when it works, converts externalities into direct costs. That's the whole point of regulation.
Once regulation makes it less expensive (to the manufacturers, or to the distributors, which becomes the same thing) to have unique default passwords on these things, they'll start having unique default passwords.
-
-
-
Monday 29th April 2024 12:22 GMT Mike 137
Actually, could do better
"Default passwords are allowed, but if they're easily discoverable online, then it will fall foul of the Act"
Yes another example of how little our legislators understand the technicalities of infosec. Unless each device has a unique default password (hardly practicable in the consumer device space), there's absolutely nothing to prevent a malicious actor buying a device and publishing the default password online. The only genuinely secure approach is for the device to be inoperative until a user password is entered (i.e. no default needed or allowed). This ain't hard to implement -- on every power up, the device checks whether a password has been created. If not, it requests one and and won't proceed with its main function until one is created.
The other two quoted requirements (security contact point and declared support lifetime) are welcome as far as they go, but we really need a requirement to comply with secure development standards so devices are intrinsically more resistant to attack. Legislation to this end is apparently in progress in the US, but currently only for devices for government use. It's a pity that ,as usual, the UK refuses to be a real leader in this domain. We always seem to be satisfied with echoing minimum standards set by others.
-
-
Monday 29th April 2024 13:26 GMT abend0c4
Re: Actually, could do better
Pretty much every network device is going to have a (uniquish) MAC address, pretty much every device has writable storage for updatable firmware (and is likely programmed in the factory) and anything that uses a password has to have somewhere writable to store the verification value, so unique defaults are perfectly doable. Passwords may not be ideal, but start with the easy wins...
-
-
Monday 29th April 2024 15:19 GMT abend0c4
Re: Actually, could do better
Sorry, the point I was making (or trying to...) is that there already has to be a means of getting unique data into every device so that part of the problem is already solved. As you say, wireless networks leak MAC addresses (and the first half can be determined from the manufacturer) so they're not in themselves a solution. And nor are serial numbers...
-
-
-
Monday 29th April 2024 16:08 GMT vtcodger
Re: Actually, could do better
As most anyone who has ever been near a manufacturing operation can tell you, the problem isn't setting a unique (or after allowing for the inevitable screwups) a near unique password on each device. One problem is telling the buyer/user exactly what their unique password is 100% of the time. Said user is going to be extremely displeased if they pay for a box then can't use it because they don't know that password. Another problem in many cases is how the vendor is supposed to authenticate over the air updates (Not that great in idea IMHO, but one which is popular at the moment) without a master password or some clue as to what the current password is.
-
Tuesday 30th April 2024 16:05 GMT Michael Wojcik
Re: Actually, could do better
Said user is going to be extremely displeased if they pay for a box then can't use it because they don't know that password.
That's why you mandate the unique password with regulation. Then displeased users have no choice, so there's no competitive advantage in not shipping with a unique password, and users are required to become a little more competent.
And, frankly, user displeasure has done fuck-all to improve IoT crap, "smart" TVs, and the like, so if I were a manufacturer I wouldn't be worried about it in the slightest.
-
-
-
-
Monday 29th April 2024 13:18 GMT Innominate Chicken
Re: Actually, could do better
Not as hard as it sounds, randomly generate a password and set it as part of initialising the data/firmware on the device. Log the serial number and PW pairs, pass them to the packaging line and print them somewhere on the paperwork that comes with the device.
All this needs is to be able to individually identify the devices at both stages, which one would hope is already tracked for traceability and QA purposes.
-
Monday 29th April 2024 13:39 GMT Mike 137
Re: Actually, could do better
"Log the serial number and PW pairs, pass them to the packaging line and print them somewhere on the paperwork that comes with the device"
Actually much more complicated to implement than requiring the user to create a password to unlock the device on first power up, and (for mass market devices) more likely to confuse non-technical users. We're not talking routers here that get set up by folks that understand at least something about the tech, but doorbells, dongles, security cameras and smart speakers. The reason the "default password" is typically e.g. '123456' is to avoid such confusion, which would be the more common the more 'random' the default was.
Just for comparison, I created a power monitor a few years back, which required calibration for accuracy. I designed the code so that the first time it was powered up it was in calibration mode (for which there were detailed instructions provided). After calibration, it would power up in operational mode. This was a much more complex initialisation process for the user than merely being prompted to create a password, but it nevertheless worked fine.
-
Monday 29th April 2024 13:25 GMT Cav
Re: Actually, could do better
Seriously? Default is not the same as generic. Most devices have unique passwords. They are set to a default value by the supplier and appear in the device documentation on on the packaging. Buy it, login and then change the password.
Only the supplier would know the default password for a particular unique device.
-
Monday 29th April 2024 13:43 GMT heyrick
Re: Actually, could do better
"Only the supplier would know the default password for a particular unique device."
Not necessarily. It's possible to extract data from the flash using the bootloader, split it out as what's the boot partition, unpack it, extract the password file, brute force it, and... tah dah, a functional password.
I didn't do this, but somebody else did which is why I can log into my little media sharer device using the wide open telnet port (duh).
-
-
Monday 29th April 2024 13:39 GMT Jason Bloomberg
Re: Actually, could do better
Unless each device has a unique default password (hardly practicable in the consumer device space)
An unguessable sequence of characters as that device's default is good enough. That is entirely practical, some have been doing that for years, and seems to be all the law is demanding.
I am not as adverse to using default passwords based on a serial number as others are. That is as equally unguessable unless an attacker knows the serial number and how the password is derived from that..
This is an attempt to trim the low-hung fruit, prevent manufacturers supplying low-hung fruit. I would agree the legislation could have gone further but it's a massive improvement on what we have allowed in the consumer market.
-
Tuesday 30th April 2024 11:44 GMT Filippo
Re: Actually, could do better
>nless each device has a unique default password (hardly practicable in the consumer device space)
I don't think it's that difficult to ship each device with a strong unique default password (that is not just the MAC, or the S/N, or whatever). The routers I've got from my recent ISPs all did just that, and they aren't exactly top shelf stuff. How much can it possibly add to the device's cost? Pennies? A couple quid? Either way, it's money well spent if it means an attacker has to come to lazy user's house and read a physical sticker.
-
-
-
-
Monday 29th April 2024 12:42 GMT Headley_Grange
How is this going to be enforceable for all that Chinese tat for sale online? The UK has no power to sue China-based sellers - they can't even make them pay VAT, FFS. It can tell Amazon, eBay, etc. to shut sellers down, but they'll just turn up a couple of hours later as a new company selling the same product with a different name. They can't go after the souks because, under current legislation, they aren't responsible for what they sell.
-
Monday 29th April 2024 13:31 GMT Doctor Syntax
Have a few trading standards inspectors visit the warehouses and seize the entire stock of non-compliant devices. Watch the net container load sent straight back. Likewise intercept and check a sample of incoming packages and seize non-compliant goods, charge VAT/duty on the rest. That'll kill the straight from China route.
-
Monday 29th April 2024 13:46 GMT Jason Bloomberg
Yes, exactly how they do it now for other prohibited, illegal, and non-compliant goods. Seizures and fines for retailers, importers, handlers, sellers, and manufacturers, will tackle most of it. Direct sales to consumers is harder but nothing they don't have to deal with already.
Even if it doesn't remove the problem entirely it will greatly reduce it.
-
Monday 29th April 2024 15:09 GMT Headley_Grange
Doesn't work. Which? did an article on dangerous heaters - all for sale on Amazon and eBay. All that happened was that Which told Amazon and eBay, got the stock answers and the products disappeared for a while before returning a few weeks later. No one got fined, prosecuted, ...., or anything really. They're probably still on sale and Bezos and the like are pocketing the profits without giving a fuck. Nothing will change.
-
Monday 29th April 2024 15:17 GMT Headley_Grange
"but nothing they don't have to deal with already"
Yes it is - it's a whole new other thing that's got to be looked for. I didn't see any announcement about the additional thousands of trading standards bodies to support this.
I think it'd be better to offer a bounty for finding non-complying products (not just for passwords, safety as well) to be paid for by fines on the retailer (Amazon, Facebook, etc.) large enough to make it worthwhile - say £20k per confirmed find. There'd be no need for additional trading standards staff and it would be better than wandering round a muddy field at night with a metal detector.
-
-
-
Monday 29th April 2024 22:28 GMT Anonymous Coward
"chinese tat"
Bearing in mind the regulators are utterly powerless and incapable of making sure imported "chinese tat" even complies with basic electrical, fire safety or emc standards then this seems act just seems a waste of ram and electrons. A seemingly good idea, but utterly unenforceable.
-
Tuesday 30th April 2024 07:29 GMT UnknownUnknown
Re: "chinese tat"
It’s more new legislation whilst previous remains almost completely enforced.
- electrical safety
- mobile phones/driving
- driving like a wanker
I was heartened to see looks like the Office for Electrical Tat looks like it was setup anew and is based in Birmingham, with only a small Londonshire Office.
Like wow !! Levelling Up! In action.
-
Tuesday 30th April 2024 13:06 GMT hoola
Re: "chinese tat"
I think it is even more basic.
Whilst people continue to buy & setup all this shite without a care in the world because it enables them to see who is at the door, switch the oven on, view the dog or power up a vibrator nothing will change.
Huge numbers of people are addicted to this crap because it is seen as cool. I simply don't give a toss if I can see who is at the door when I am out or know what the temperature of the fridge is on an app. If it is any of the crap delivery people they just leave it on the doorstep anyway. Having a recording of them doing it is worthless. The delivery company already knows they have done it as most is "photo on delivery".
A friend was proudly showing me some app on his phone for his solar panels and battery with funky diagrams etc. The bit that made me chuckle is he lectures in cyber security at a university.
-
-
Monday 29th April 2024 12:43 GMT Stu J
A good start...
...but companies should also be mandated to provide perpetual local control of all devices.
Being reliant on a cloud service that could shut down (or ramp up subscription costs) tomorrow on the whim of a company (or whoever decides to buy them) is not a good position for consumers to be in.
It doesn't even have to be a "both" - even making firmware available that provides the ability to read data from and send instructions to the device locally, and allowing users to load that firmware if they don't want to be locked in to a cloud model would be better than the status quo.
I've nothing against manufacturers paywalling more intelligent functionality, storage etc behind a subscription, but the raw device capabilities should be accessible and documented if the consumer requires it and wants to roll their own integrations.
-
Monday 29th April 2024 14:54 GMT frankyunderwood123
Not enforceable
There's no way this is going to be able to be enforced.
Sure, the big brands will play along, but there's hundreds of manufacturers, most in Asia - China - just flooding the market with products.
Some cheap and nasty, others cheap and not that bad.
To enforce this, means getting Amazon to enforce the new laws on sellers.
Given Amazon barely even pay tax and get away with it, good luck getting them involved.
Also, AliExpress continues to gain popularity in the UK - despite slow shipping times and often exceptionally questionable goods - the crazy low prices attract people.
We're no longer in a world of Curry's or Maplin (no longer exist) or Argos dominance of tech products - that ended well over a decade back.
We're in a world where you can get product shipped from anywhere on the planet.
-
Monday 29th April 2024 16:50 GMT Version 1.0
Create 100% reliable passwords.
OK so you can record and write down your password e.g "Admin123" but just remember that's only a hint because the fully functional and safe password would be "Gweinyddol123" - just never create passwords in English because that's the worlds most common language researched by hackers. Even if they are using AI then it's a bet that hidden Welsh will never be hacked. I've started using Welsh passwords since the early days, just planning (and 100% successful) never to get hacked.
-
Tuesday 30th April 2024 01:03 GMT steviebuk
Re: Create 100% reliable passwords.
Had one lady at work write her password on the noticeboard in her office. I smirked a bit as she said "No one can read it, I'm the only one left in the building that can read and write shorthand". And she's right. At the new place I mentioned this story to a new starter to only be asked "What's shorthand?". I felt old.
-
-
Tuesday 30th April 2024 06:55 GMT greenwood-IT
A far simpler option would be to allow a default password but insist on it being changed on first use.
The main advantage would be that you can then easily gain access following a Factory Reset. The idea of resetting a device and THEN having to find a sticky label for the password :-(
The idea of a "Security Support Contact" and a published "Best Before" date would be handy, but I bet a bunch of the cheap IoT companies would just go bust and rebrand (if they have a brand!) every year.
-
Tuesday 30th April 2024 13:10 GMT Zola
A "default" password IS permitted after a factory reset, which must then be reset by the user.
An even easier solution is for there to be NO PASSWORD after a factory reset, and the user has to set a password on first login.
There's simply no need for a "default" password at all once the device has been factory reset. In fact, having a "default" (and likely well known) password is what got us into this mess in the first place.
-
-
Tuesday 7th May 2024 00:17 GMT Grogan
How is someone supposed to recover a device from corrupted settings when they most likely won't know the original password of the device, after a reset? Yeah sure, they kept the piece of paper /s
I would simply tell people to throw the devices away and buy new ones, because my time is too expensive to waste on that. How would manufacturer's tech support even help you unless there's a backdoor or another "default" password that can be discovered and publicized?