UK lays down fresh legislation banning crummy default device passwords
ID: 2f8d09be-e69d-529a-a6e7-2a2925a3d24a
STIX ID: report--2f8d09be-e69d-529a-a6e7-2a2925a3d24a
Feed Name: The Register (Security)
The UK’s Product Security and Telecommunications Infrastructure (PSTI) Act now mandates baseline security for consumer smart devices, prohibiting easily discoverable default passwords, requiring a public point of contact for reporting vulnerabilities, and disclosure of minimum security update periods. Enforced by the Office for Product Safety and Standards with penalties up to £10 million or 4% of global revenue, the law is broadly welcomed as a foundational step; however, experts note it covers only a subset of ETSI recommendations and question how rigorously it will be enforced, with the NCSC issuing complementary guidance on strong passwords.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
