UK becomes first country to ban default bad passwords on IoT devices

April 30, 2024
The Record
Contributed by: Drex DeFord
Seven years after a significant cyberattack disabled access to major US websites using a distributed-denial-of-service (DDoS) attack via the Mirai botnet, the UK has legislated to counter similar threats by becoming the first country to ban default guessable usernames and passwords on IoT devices. The Product Security and Telecommunications Infrastructure Act 2022 sets new minimum security standards for IoT device manufacturers, requiring them to inform consumers about the duration of security updates and forbidding weak default passwords to reduce the risk of cyberattacks. This legislation, enforced by the Office for Product Safety and Standards, also subjects non-compliant manufacturers to fines or recalls, highlighting a proactive approach to enhancing cybersecurity in an increasingly connected world.
