One of Apple ’s main goals with HomeKit was to make smart home devices secure. The UK government has announced that it wants to help achieve this goal by requiring all devices to meet three key security requirements . First, all passwords for internet -connected devices must be unique and cannot be recovered by any global factory reset . IoT device manufacturers must provide a public point of contact so that anyone can report a vulnerability and take action in a timely manner. They must also explicitly state the minimum period for which the device will receive security updates at the point of sale, either in- store or online.

Apple's HomeKit protocol aims to secure smart home devices by addressing security at a more fundamental level. Devices—and whoever controls them—must use encrypted communications. It must ensure that the device is authenticated before sending a command, and the device must verify that the "commander" is trustworthy before obeying.
British Communications Minister Matt Warman said the aim was to make the UK the safest place to be online, introducing innovation that enhances and enhances modern technology. He also said the law would allow businesses to make and sell internet-connected devices to tackle and thwart hackers who threaten privacy and security. The government said it intended to implement the law as soon as possible, although it would initially be voluntary rather than mandatory, with officials overseeing effectiveness and efficiency.
Finally, it is noted that even avoiding the use default passwords is much better than nothing. There are still a huge number of network cameras with default passwords that many owners do not bother to change.
