51 points

Don’t worry, this law doesn’t affect luggage.

permalink
report
reply
15 points

I have 2fa for my luggage.

permalink
report
parent
reply
2 points
*

Something I have: my luggage

Something else I have: bolt cutters

It’s an expensive system but it works for me.

permalink
report
parent
reply
43 points

Brands have to publish contact details so that bugs and issues can be reported, and must be transparent about timings of security updates.

The non headline part of the law sounds great to me.

permalink
report
reply
25 points
*

Yeah I read the headline and thought what, then read the article and it actually seems pretty reasonable.

Devices should not come with a username of ‘admin’ and a password of ‘admin’, it’s a disaster waiting to happen.

permalink
report
parent
reply
7 points

Is it really on the device manufacturer that people don’t change the default password? That’s advice that’s been around so long and it’s the first thing they tell you in computer training.

Default passwords have their use cases for testing, ease of set-up, and for device recovery.

permalink
report
parent
reply
15 points
*

Yes, it should be. Sending someone a device with usr/pwd as admin/admin, for example, is completely reckless if it doesn’t prompt the user to change it during setup.

it’s the first thing they tell you in computer training.

You shouldn’t need specialist training to use basic home products, and you shouldn’t have to put up with extremely compromised security in the event of you not being technically-minded or you blitz through installations pressing next next next. Not everyone is or can be technically minded.

Plenty of products have protections in place designed to protect users in the realistic event that not everything will be used flawlessly 100% of the time.

PCs aren’t shipped to you with always-on root-level access, gas hobs often have features to turn themselves off if they detect they’ve not been ignited, cars have all kinds of safety features, pills come in pop-packs to discourage taking a load at once by swigging a bottle, Switch cartridges taste like shit to stop babies from choking on them, etc. sure, not all of these should be legally required, but some absolutely should be.

permalink
report
parent
reply
30 points

12345? Thats amazing, I have the same combination on my luggage!

permalink
report
reply
8 points

Ha, mine is 10 times more secure!

permalink
report
parent
reply
12 points

123450?

permalink
report
parent
reply
11 points
*

Usually, an impact study is made before such type of laws are made:

  • if this law is enacted, how much will it cost to the manufacturers to update their factory settings?
  • how will this be impacted on the device cost in the UK compared to other markets?
  • how many users will get stuck when losing the unique ID of the device, what are the recovery procedures, how costly is it to end users?
  • how many users will be protected by the measure and what cost for society does it represent?
  • how many users will set a dumb password anyhow and what is the cost for society?

I’d be curious to see the impact study, as many of those are actually botched.

permalink
report
reply
10 points

Most routers already have non-standard passwords by default. At least in EU. I’m not sure which devices besides routers and IoT peripherals are affected by this bill.

permalink
report
parent
reply
1 point

All of them I’ve seen do use non-standard passwords for the web access portion, however it’s been a mixed bag for the admin controls on the router OS itself. It’s often just admin/admin.

Which is crazy. I could, if I were inclined, log into the router in someone’s house/business if they haven’t changed the admin password, but they have provided me with a password to access the web. Most people don’t bother changing the admin password.

permalink
report
parent
reply
8 points

a user set weak password is infinitly more strong than a known default.

admin
admin

permalink
report
parent
reply
1 point

That makes a strong password a million times infinite strong.

permalink
report
parent
reply
7 points

I wonder about raspberry pi - it’s the image you download that has the known user and password.
It might mean that you can’t sell one with a pre-imaged, pre-installed sdcard unless you customised the image.

permalink
report
reply
7 points
*

It’s very easy to remove that and ask for a password on first boot. It could literally be one line in a shell script. They could put it in a text menu if they want to get fancy.

More professional (non-hobby) RP based devices probably aren’t using stock vanilla Raspbian anyway.

permalink
report
parent
reply
3 points

stock vanilla Raspbian anyway.

Raspberry pi OS != Raspbian

Those are two completely separate and different OSes.

permalink
report
parent
reply
1 point
Deleted by creator
permalink
report
parent
reply
1 point

Force of habit. I’ve been working with Pis for a while, long before the name change.

permalink
report
parent
reply
2 points

You can already use a tool in the rpi imager to set the default login for your image.

permalink
report
parent
reply

Technology

!technology@lemmy.world

Create post

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


Community stats

  • 17K

    Monthly active users

  • 10K

    Posts

  • 466K

    Comments