HomeSecurityCalifornia: New security law for IoT devices

California: New security law for IoT devices

A new law passed in California will prohibit IoT device manufacturers from selling their devices with default passwords, but experts want something more. The new law will take effect in January 2020, and aims to make IoT devices more secure, preventing attacks like those that have occurred in recent years, such as the Mirai botnet.

iot california devices secure

The law is aimed at manufacturers of devices that can access the internet in any way, or have Bluetooth capabilities, and will force manufacturers to have a different default password for each device they sell, or require the user to change the device's password the first time they turn it on. This way, it will not be possible to breach all devices that use the same password.

This technique first appeared in 2016 with the Mirai, but many variants have been released since then, the most recent of which was detected last week, named “Torii”.

But experts believe that this is not enough. “While this change may save many devices, it does not protect users from other vulnerabilities, such as SQL injection or phishing attacks. Even if a user uses a strong password, malicious hackers can still compromise the device. In the case where a user uses the same complex passwords on all their devices and online services, they now have another vulnerability to worry about.

Finally, security researchers suggest that the law be amended, and that it be appropriately structured so that manufacturers are required to provide patches and security fixes for their devices for a certain period of time.

 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS