The United Kingdom (UK) government has introduced a new bill that will require manufacturers and distributors of technology products to ensure their devices meet minimum safety standards, with heavy fines if they fail to comply.

See also: Apple: They ask to stop plans to scan devices for child abuse
Device manufacturers will be prohibited under the Product Security and Telecommunications Infrastructure (PSTI) bill from selling mobile devices, televisions, speakers, games and other digital devices that do not meet security requirements set out in the law. This includes using default passwords that are easy for hackers to guess on connected products.
All passwords preloaded on new devices must be unique “and not resettable by a global factory reset.” The bill seeks to prohibit the use of simple default passwords such as “admin” or “password” that come with devices, as these are commonly targeted by hackers.
The new legislation would also require companies to disclose the release dates of security updates for their products and create an easy public reporting system so researchers can quickly report vulnerabilities found in those devices. Manufacturers would also have to inform customers at the point of sale when any security flaws in connected devices will be fixed.
See also: NSA: Guidelines on how to secure wireless devices

The government reported 1.5 billion attack attempts on IoT devices in the first half of 2020 alone.
See also: AI: Tool predicts the failure of electronic devices
If their products fail to comply with the new rules, device manufacturers could face fines of up to £10 million or 4% of their global revenue. Once the bill is passed, a regulatory body will be created to oversee the implementation of the new rules.
Information source: androidcentral.com
