Networking-Forums.com

Professional Discussions => Security => Topic started by: deanwebb on April 12, 2022, 01:12:39 PM

Title: Laws Against Default Passwords
Post by: deanwebb on April 12, 2022, 01:12:39 PM
Found this in my research today: https://techcrunch.com/2018/10/05/california-passes-law-that-bans-default-passwords-in-connected-devices/

It's a start, I like how it requires a unique password for each device and for a password change after first logon.

Title: Re: Laws Against Default Passwords
Post by: Otanx on April 12, 2022, 01:33:54 PM
So that law was passed in 2018, and was supposed to be enforced starting in 2020. Wonder how enforcement is going. I am pretty sure some of the gear I work with has default passwords, and don't force changes. Maybe they don't sell those in California.

-Otanx
Title: Re: Laws Against Default Passwords
Post by: deanwebb on April 13, 2022, 08:56:33 AM
Could be. I read more on it and both the USA and EU have guidelines that stop short of assessing fines. The UK, however, just passed a law that assesses fines for vendors that make gear with default passwords.

I hope that the legislation also extends to hard-coded root accounts.

Network engineer whose gear was pwned because attacker used a default root account:

:facepalm1: