Slashdot Mirror


California May Ban Terrible Default Passwords On Connected Devices (engadget.com)

According to Engadget, the California Senate has sent Governor Jerry Brown draft legislation that would require manufacturers to either have to use unique preprogrammed passwords or make you change the credentials the first time you use it. "Companies will also have to 'equip the device with a reasonable security feature or features that are appropriate to the nature and function of the device,'" reports Engadget. From the report: If Brown signs the bill into law, it will take effect at the beginning of 2020. But critics claim the wording is vague and doesn't go far enough in ensuring manufacturers don't include unsecured features. "It's like dieting, where people insist you should eat more kale, which does little to address the problem you are pigging out on potato chips," Robert Graham of Errata Security said in a blog post. "The key to dieting is not eating more but eating less." Given the huge number of connected devices available, it's also not clear how the state plans to enforce and regulate the rules.

155 comments

  1. About Time by Anonymous Coward · · Score: 1

    About time, its a good start. But devices should also have a 'BACKDOOR INSTALLED" sticker if that is the case.
    And another sticker 'Device will be unsupported after 1 2 or n years. This way consumers will discriminate against throw away trash
    And a fine if string length overflows happen because of lazy coding and lazy compiles.
    You would have thought the FCC or similar would have demanded this decades ago, or a list where you can scan your device and find out if defective with no firmware upgrades available.

    1. Re:About Time by AvitarX · · Score: 5, Insightful

      I like easy default passwords.

      I want to be able to hard reset my device and get it setup without a reference. I don't want losing the paper where I wrote it's default password to brick the device on a hard reset.

      It's more challenging better to have am easy default, and force a change of password during the setup.

      --
      Wow, sent an e-mail as suggested when clicking on "use classic" banner, and got a fast response that addressed my msg
    2. Re:About Time by Anonymous Coward · · Score: 0

      Default password followed by forced change doesn't work because there is still a time window where your device has a default password. An attacker can log in and update the firmware to one with a backdoor. Then the user changes the default password thinking he has secured the device, but it's too late.

    3. Re:About Time by Gilgaron · · Score: 1

      They mold in serial numbers, surely they can mold in the default password or do a resin impregnated label that ought to last as long as the device.

    4. Re:About Time by ctilsie242 · · Score: 2

      What might be the best thing is an e-Ink display or a cheap LCD display. When the device is hard reset, the display will show a random 10-20 digit code on it, which will be the temporary password for the device. Then, once the device is logged into, it will force a password change.

    5. Re:About Time by AmiMoJo · · Score: 1

      Many devices come with a strong default password printed on the case. Can't lose it because it's on the device permanently. It's a good enough password for the user to keep using without changing it, and the physical security of it being in your house is adequate for stuff like WiFi and Bluetooth pairing codes.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    6. Re:About Time by AvitarX · · Score: 1

      I've had a few travel routers, and they all have this wear off pretty quick. Not to say a device could do it in a way that it won't wear off, but they tended to in my experience.

      It looks like the law allows for the simple default plus forced change though (that's what I get for not reading TFS).

      --
      Wow, sent an e-mail as suggested when clicking on "use classic" banner, and got a fast response that addressed my msg
    7. Re:About Time by Anonymous Coward · · Score: 0

      When the device is hard reset, the display will show a random 10-20 digit code on it, which will be the temporary password for the device. Then, once the device is logged into, it will force a password change.

      If it is reasonably random, then there is no need to "force" a password change. Most users will change it to something memorable immediately, and some users will simply copying the nonsense string into their notebook and use it as-is. If it's already at last as unpredictable as manual passwords, both of those are secure reactions.

    8. Re:About Time by AvitarX · · Score: 1

      Just require a physical touch to begin the initial setup process.

      --
      Wow, sent an e-mail as suggested when clicking on "use classic" banner, and got a fast response that addressed my msg
    9. Re:About Time by Anonymous Coward · · Score: 0

      The default password can be put on the device just like (e.g.) serial numbers are now. Heck: if the law states that each device shipped needs a unique default password just re-use the S/N for that purpose as well. No separate piece of paper needed.

    10. Re:About Time by Anonymous Coward · · Score: 1

      Most people will change it to "password" which sort of defeats the object.

    11. Re:About Time by nitehawk214 · · Score: 1

      My home Verizon router is both. It has a unique default password printed on a sticker on the device. If you reset it to the defaults that becomes the password.

      And the first thing you do to the device when you set it up is to reset it to the defaults with a button on the device.

      Now, when I forget the password that I put into it, I can simply reset the device and use the password on the sticker.

      --
      I'm a good cook. I'm a fantastic eater. - Steven Brust
    12. Re:About Time by Darinbob · · Score: 1

      I like that idea of it showing up on the device. I'd go further though. If the random password is suitably random, then don't let the user change the password. Instead have a button that creates a new password and displays that.

      The snag though, is that now you have to have the actual text of the password stored in the device, which can mean that there's a way to get ahold of that password remotely. And manufacturers aren't going to voluntarily add a complicated secure module when they can just print a sticker instead.

    13. Re:About Time by Anonymous Coward · · Score: 1

      Right now it's "power it on to begin the initial setup process". How does your extra physical button help in any way?

    14. Re:About Time by Anonymous Coward · · Score: 0

      It's a good enough password for the user to keep using without changing it

      Except it isn't. You don't know who else has that password. Someone could have opened it prior to you and re-shrink-wrapped it prior to it ending up in your hands. Someone could have hacked the factory printer that made the label to send them copies of each password / serial number / mac address / etc. Hell the system that generated the password may have been flawed and generated insecure passwords by complete accident.

      What are you going to do now? Require officially licensed shrink-wrappers? Mandate the Secret Service closely monitor and control Label Printers? Legally mandate verified password generators and hire mathematicians to certify it's effectiveness?

      Past a certain point, you have to take security into your own hands. The world cannot and should not shield you from every little thing in life. Mandating legislation like this is just yet another desperate and misguided plea by the masses to maintain Zombie Jobs' 1989 view of computers in spite of the massive changes in both how we use computers, and computers themselves, that have occurred since then. That desperate and misguided plea has cost us all enough harm. Don't fall for it again, you're just prolonging the inevitable.

    15. Re:About Time by ctilsie242 · · Score: 1

      The main reason for the forced change is to transfer all responsibility of security to the user as early as possible. If the user wants "hunter2" or "password", that is up to them. It also mitigates any issues, should the password generator for the device wind up being weak, or the screen the password displayed on limited in how many characters it can display. I would say 8 characters would be minimum displayed on the screen, provided it is changed almost immediately.

    16. Re:About Time by rpstrong · · Score: 1

      Simply do not connect to the internet until the password is changed.

      Was that so tough?

    17. Re:About Time by Agripa · · Score: 1

      I want to be able to hard reset my device and get it setup without a reference. I don't want losing the paper where I wrote it's default password to brick the device on a hard reset.

      But think of the sales opportunities!

    18. Re:About Time by AvitarX · · Score: 1

      If the process was send it firmware, then push the button.

      The window would be incredibly short. I'd argue short enough as to be zero risk.

      Someone would have to upload a new firmware between the person setting it up uploaded one, and when they pushed the button.

      --
      Wow, sent an e-mail as suggested when clicking on "use classic" banner, and got a fast response that addressed my msg
  2. Correct me if I'm wrong but by Jarwulf · · Score: 2

    aren't most of these account compromises due to stuff like an incompetent company leaving its database in plaintext or some kid phishing it from or fooling an employee somehow instead of some master hacker bruteforcing individual passwords that don't follow silly rules like having upper case and symbols?

    1. Re: Correct me if I'm wrong but by datavirtue · · Score: 3, Insightful

      Yes....but California is going to save the world with laws.

      --
      I object to power without constructive purpose. --Spock
    2. Re: Correct me if I'm wrong but by Anonymous Coward · · Score: 0

      Absolutely. Anything more would hinder innovation (the invention of new ways to separate marks from their money).

    3. Re:Correct me if I'm wrong but by nine-times · · Score: 1

      Well that's the sort of thing you hear about, but... well, first, in order to see that the database is in plaintext, you have to get access first. It's not uncommon for people to get into the systems because of password reuse or weak passwords or default passwords.

      Also, you don't hear much about the compromises that are due to default passwords because it's not a big scary unexpected security flaw. It's written off as, "Yeah, that guy's dumb for leaving the default password." But I think when you're designing these things, you have to kind of assume that the guy setting it up is going to be stupid, and therefore make some effort to make the defaults secure.

      So yes, the whole "default password" thing is a genuine problem. In fact, you might go as far as to say, the whole "password" thing is a problem, but it's not clear what the solution is, and it doesn't look like anyone is going to fix it.

    4. Re: Correct me if I'm wrong but by Anonymous Coward · · Score: 1

      The problem in this situation is NOT companies. It is morons who keep default passwords. California would like to continue to allow moron companies to survive, which is the antithesis of natural selection. Remember, corporations are people my friend.

    5. Re: Correct me if I'm wrong but by Anonymous Coward · · Score: 0

      Meanwhile, because they always do the opposite of what liberals do, the rulers of Magaland are going to save your personal finances by encoding in law you the FREEDUMB!! to set your internet bank password to 'password". USA!!! USA!! USA!!!

      Love how lefty libs counter idiotic dumb lefty lib laws by trying to make up that their rivals as dumber. Instead why don't you just not make dumb laws so that we don't laugh at you?

    6. Re:Correct me if I'm wrong but by Junta · · Score: 1

      Well, in this case the consequence of well known default passwords are the various botnets of embedded devices, which happen very often.

      --
      XML is like violence. If it doesn't solve the problem, use more.
    7. Re: Correct me if I'm wrong but by desdinova+216 · · Score: 1

      is lefty libs the new appy app appers?

  3. Draft Legislation? by Anonymous Coward · · Score: 0

    According to Engadget, the California Senate has sent Governor Jerry Brown draft legislation...

    Looking at the actual bill, it has already passed in both the CA Senate and Assembly.

    That makes it more than a draft. That's a bill ready to be signed into law, or possibly vetoed.

    Maybe it means something else to other people, but when I send someone a draft, it's to solicit comments.

    https://www.senate.ca.gov/legislativeprocess

    1. Re: Draft Legislation? by Anonymous Coward · · Score: 0

      Looks like you are unfamiliar with the California legislature's process.

      Or Slashdot's. This is actually about a week out of date, so when they sent the packet with this law(along with others) to the governor, it was technically a draft as they could easily amend it before their final vote.

      You know, if they wanted to save Springfield from a meteor or support the pornographic arts.

  4. Good First Step by mentil · · Score: 5, Funny

    Now instead of a default router password, users will be prompted to change it, thus setting it to 'Password1'.
    Progress!

    --
    Corruption is convincing someone that the selfless ideal is the same as their selfish ideal.
    1. Re:Good First Step by Anonymous Coward · · Score: 1

      They just need to make a law against that too. Duh

    2. Re:Good First Step by Anonymous Coward · · Score: 0

      If you're so dumb to choose such an insecure password you deserve the consequences. At least it won't be the device's fault for the weak password.

    3. Re:Good First Step by Anonymous Coward · · Score: 0

      Password1? That's amazing! I've got the same password on my ruter!

    4. Re:Good First Step by aaarrrgggh · · Score: 1

      C'mon, that isn't secure... try "Password1!"

      Installed OpenHAB to look at it for home automation, and I just kept cringing at how miserable the security model is and just how hard they have made it to put it in a non-routeable VLAN. While this bill doesn't address everything by any means, the "reasonable minimum protections" concept needs to be enshrined somewhere.

    5. Re:Good First Step by Anonymous Coward · · Score: 0

      Now instead of a default router password, users will be prompted to change it, thus setting it to 'Password1'.
      Progress!

      Depends on the final wording. It may be that an OEM has to:

      * (a) have a unique default password for each device, AND / OR
      * (b) have the same default password but for a change on first login

      So if they just take a device's serial number and make that the default password and they're done. If they want to get fancy, if the S/N is all-numeric, they could either pass it through Diceware to generate words.

      Or, optionally, have both.

      However, IMHO, I think either of the above two options is better than the general status quo.

    6. Re:Good First Step by Highdude702 · · Score: 1

      They should pass laws making it illegal to break the law.

    7. Re:Good First Step by Agripa · · Score: 1

      Now instead of a default router password, users will be prompted to change it, thus setting it to 'Password2'.

  5. dieting? Don't even *think* about it. by Anonymous Coward · · Score: 0, Interesting

    Robert Graham of Errata Security said in a blog post. "The key to dieting is not eating more but eating less."

    As so many people who are talking about "dieting" they are both wrong, and have a very short-sighted view.

    "Eating less" seems to be the answer, but results in hunger pangs, leading to the person not being able to think about anything else than food, and thus stress himself out. And guess what that tends to lead to ...

    So, start with eathing three good, full meals. That definitily helps to quench the snack attacks.

    But foremost, try to figure out why you are eating all that stuff (did I already mention stress ? I think I did), and try to get it clear in your mind.

    Being aware of what makes you eat definitly helps in breaking the habit. Ofcourse, as you now aware of what bothers you you also have a chance to eliminate the cause of that stress.

    1. Re:dieting? Don't even *think* about it. by Nidi62 · · Score: 0

      "Eating less" seems to be the answer, but results in hunger pangs, leading to the person not being able to think about anything else than food, and thus stress himself out. And guess what that tends to lead to ...

      If you are gaining weight, in most cases it is because you are eating too much (or at least too much of the wrong things). With so many meals in the US having a calorie count in the 4 digits, simply reducing the size of meals and eating until "not hungry" instead of "feeling full" will allow you to lose weight without getting hunger pangs. If you are getting hunger pangs then you are starving yourself. And never cut out a food completely unless directed to by a doctor: doing so only causes cravings that lead you to break your diet (have that donut every now and then, eat some pizza). Following this philosophy let me lose 30 lbs in 3 months back in college (10 years ago) and I am down about 15 since the beginning of August. Of course this does include regular exercise as well as any effective diet should.

      --
      The only thing necessary for evil to triumph is for it to be pitted against a slightly greater evil
    2. Re:dieting? Don't even *think* about it. by Anonymous Coward · · Score: 0

      The key to loosing weight is exercise more. I eat anything and everything that I want. But I do ride a bicycle every day. I'm 6'1" and average in between 178lbs and 182lbs.

    3. Re:dieting? Don't even *think* about it. by Bongo · · Score: 0

      Robert Graham of Errata Security said in a blog post. "The key to dieting is not eating more but eating less."

      As so many people who are talking about "dieting" they are both wrong, and have a very short-sighted view.

      "Eating less" seems to be the answer, but results in hunger pangs, leading to the person not being able to think about anything else than food, and thus stress himself out. And guess what that tends to lead to ...

      So, start with eathing three good, full meals. That definitily helps to quench the snack attacks.

      But foremost, try to figure out why you are eating all that stuff (did I already mention stress ? I think I did), and try to get it clear in your mind.

      Being aware of what makes you eat definitly helps in breaking the habit. Ofcourse, as you now aware of what bothers you you also have a chance to eliminate the cause of that stress.

      If you lookup low carb high fat (LCHF), ketogenic, and carnivore proponents and experimenters, they're the ones getting the long lasting results.

      Gary Taubes did his now famous investigation into the history of nutritional science and found how it went all to pot when it shifted to USA and ignored the earlier, actually good scientists, in Germany and Austria, and what they had already been discovering.

      In essence, yeah, there are things which cause people to gain weight, and meanwhile, the meme of advising people to "eat less" is really terrible and counterproductive advice. And don't worry, no laws of thermodynamics are ever broken. It is just that the body is complex and "eat less" does not focus on the right stuff.

      If your body, regulated by hormones, enters a mode where it is working to store fat, you WILL store fat no matter what you think you are doing to "eat less" and "exercise more". I gather in animal studies, the animal can even cannibalise its own muscle in order to store fat whilst being on a calorie restricted diet.

      So the key is to choose foods (and even times of day when you eat) which don't set your body into this mode where it is driving to store fat all the time.

    4. Re:dieting? Don't even *think* about it. by Nidi62 · · Score: 1

      If you lookup low carb high fat (LCHF), ketogenic, and carnivore proponents and experimenters, they're the ones getting the long lasting results.

      I call myself "semi-keto". Greatly reduced carbs (was eating rice probably 3-4 times a week and potatoes 2-3 times a week), but also trying to stay away from really high fat (cook mostly with olive oil, not butter). Pretty sure I haven't gone into ketosis but still down about 15 lbs since Aug 1 and it's still a pretty filling diet.

      --
      The only thing necessary for evil to triumph is for it to be pitted against a slightly greater evil
    5. Re:dieting? Don't even *think* about it. by drinkypoo · · Score: 1

      I call myself "semi-keto". [...] Pretty sure I haven't gone into ketosis

      That's not even vaguely semi-keto, then. Keto is short for ketogenic, not for low-carb. And it isn't low fat, either. All you're doing is calorie reduction, which has no relation to the ketogenic diet whatsoever.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    6. Re:dieting? Don't even *think* about it. by Bongo · · Score: 1

      If you lookup low carb high fat (LCHF), ketogenic, and carnivore proponents and experimenters, they're the ones getting the long lasting results.

      I call myself "semi-keto". Greatly reduced carbs (was eating rice probably 3-4 times a week and potatoes 2-3 times a week), but also trying to stay away from really high fat (cook mostly with olive oil, not butter). Pretty sure I haven't gone into ketosis but still down about 15 lbs since Aug 1 and it's still a pretty filling diet.

      Yes, I gather the point at which people go into ketosis will be different for different people. As the other person said, that's not what keto looks like on paper, but then, if you are eating few enough carbs that you can manage to go into a fasting state overnight, whilst asleep, you might find you are in ketosis by the time you wake up, especially if it has been over 12 or maybe 16 hours since last eating.

      Unfortunately the testing strips are expensive, but they're interesting to use. I do full fat, lots of fat, and fat fat fat, and pretty much almost no carb most days, and whenever I try testing my blood, I'm in ketosis. But I slid into that over many years.

    7. Re:dieting? Don't even *think* about it. by brantondaveperson · · Score: 1

      Let me guess. You're under 40.

  6. Its the nanny state by Anonymous Coward · · Score: 1

    Go figure a somewhat reasonable default is replaced by a consumer who decides they cannot remember the password so they change it to 12345.

  7. Re:It should be by Anonymous Coward · · Score: 5, Interesting

    all building a single OS for IoT with security built in

    You think "security" is something that can be "built in." Security in software development is a mindset. How does having a secure operating system help when the web frontend developer doesn't understand how to correctly validate passwords.

    updated everytime a change happens and then have this open sourced to provide greater security and code verification.

    While having the source code available is helpful to see if there are security issues, that doesn't mean they will be found. Open source doesn't provide for greater security though. Open source == licensing model, not a security process.

    With many software projects, open source or closed, there are often only a few people who understand the software well enough to even notice those bugs.

    I don't think forcing a particular operating system down vendors throat is the solution. My idea is, everytime a vendor has a security issue on their device, I want a refund. They sold me a defective device with defective software. We need to stop calling software buggy and call it what it really is, DEFECTIVE.

  8. at least it's a start by sad_ · · Score: 0

    sure, as with any law it will be incomplete, contain loopholes and be vague in certain areas, but at least it is better then nothing.
    default passwords are a big part of security issues of IoT devices, so if we can already scrap that of the list of things to worry about, that can only be a good thing.

    --
    On a long enough timeline, the survival rate for everyone drops to zero.
    1. Re:at least it's a start by Anonymous Coward · · Score: 0

      Nothing would be better compared to a law that is incomplete, full of loopholes, vague, with little enforcement possible, and used selectively as a political tool.

      But as usual you proved why Democrats and Republicans keep getting elected.

    2. Re:at least it's a start by DigressivePoser · · Score: 1

      Nothing would be better compared to a law that is incomplete, full of loopholes, vague, with little enforcement possible, and used selectively as a political tool.

      But as usual you proved why Democrats and Republicans keep getting elected.

      Yup, you are correct. Then on top of that we can add Civil Asset Forfeiture. Govt: We are keeping your iPhone X because it was used during a violation of the password law.

      Then there will be the #1234 movement. In the future, a conservative Supreme Court nominee will get borked because of a weak password used on a device 35 years ago was in violation of the law. Some ideologically driven IT person will rat the nominee out with a letter sent to 120 year old Senator Feinstein.

  9. Next on the agenda... by Cornwallis · · Score: 5, Funny

    I've also heard there are new laws in the planning that will require everyone in California be happy and rich.

    Can't wait to see how those are enforced.

    1. Re:Next on the agenda... by theurge14 · · Score: 1

      Indeed, let's wait for the free market in California to resolve this problem on their own!

      Please let me know when that happens.

    2. Re: Next on the agenda... by Anonymous Coward · · Score: 0

      I've also heard there are new laws in the planning that will require everyone in California be happy and rich.

      Ironically, Cornwallis, those were written over 200 years ago.

      We the People of the United States, in Order to form a more perfect Union, establish Justice, insure domestic Tranquility, provide for the common defence, promote the general Welfare, and secure the Blessings of Liberty to ourselves and our Posterity, do ordain and establish this Constitution for the United States of America.

      California's Constitution codified similar principles:

      All people are by nature free and independent and have inalienable rights. Among these are enjoying and defending life and liberty, acquiring, possessing, and protecting property, and pursuing and obtaining safety, happiness, and privacy.

      I'd expand further, but substantially, yes, that is, in fact, the fundamental duty of the state and all its laws. This is in contrast to say, Glorification of God and the King of England as you may believe.

    3. Re:Next on the agenda... by Anonymous Coward · · Score: 0

      They could incorporate that Gross National Happiness index of Bhutan in California as well. It might be a natural fit.

    4. Re:Next on the agenda... by Anonymous Coward · · Score: 0

      The free market isn't there to solve that problem. That is solely up to you and your effort. The free market can't make a worthless person rich any more than the government can.

    5. Re:Next on the agenda... by Agripa · · Score: 1

      I've also heard there are new laws in the planning that will require everyone in California be happy and rich.

      Can't wait to see how those are enforced.

      Everybody will be required to discard needles and feces in the streets. When everybody is special, nobody is.

  10. Have they really thought this through? by vtcodger · · Score: 4, Insightful

    OK. I drop my toothbrush and it breaks. So I go to the store and find all six of the toothbrushes I can choose from are internet connected. I pick one, go home, plug it in. Now I enter a new password. How do I do that? It's a toothbrush.

    ------

    My (conceptual and imaginary) grandmother buys a new "smart" TV. (Seriously, "They" apparently don't make dumb TVs any more). She plugs it in getting many of the connections right. It asks (in colloquial Latvian because it's a bit confused about where it is) for a new password. She at least has an input device-- the remote. She pushes random buttons until the weird prompt(s) go away. Congratulations grandma, you've set an unknown password and effectively bricked your new TV. Who is going to unbrick it? How?

    -----

    I'm not sure the world needs politicians "solving" problems nobody understands. Quite likely a case of "Now you have two Problems"

    --
    You can't see ANYTHING from a car, You've got to get out of the goddamned contraption and walk...Edward Abbey
    1. Re:Have they really thought this through? by Anonymous Coward · · Score: 0

      There is the possibility of unique passwords being issued with each device.
      Which would fix the toothbrush problem, and the (wierdly functioning) TV.

      My internet router did this (well, I assume that the default wifi password isn't the same as my neighbour's one).

    2. Re:Have they really thought this through? by AmiMoJo · · Score: 1

      Manufacturers will avoid those problems because they don't want a huge number of returns. They will set a decent default password, as many already do.

      When thinking about these consumer laws you have to remember that manufactures always want to avoid customers having problems with their products, at least until the warranty expires, because most places make it their problem to fix it.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    3. Re:Have they really thought this through? by Anonymous Coward · · Score: 0

      OK. I drop my toothbrush and it breaks. So I go to the store and find all six of the toothbrushes I can choose from are internet connected. I pick one, go home, plug it in. Now I enter a new password. How do I do that? It's a toothbrush.

      ------

      My (conceptual and imaginary) grandmother buys a new "smart" TV. (Seriously, "They" apparently don't make dumb TVs any more). She plugs it in getting many of the connections right. It asks (in colloquial Latvian because it's a bit confused about where it is) for a new password. She at least has an input device-- the remote. She pushes random buttons until the weird prompt(s) go away. Congratulations grandma, you've set an unknown password and effectively bricked your new TV. Who is going to unbrick it? How?

      -----

      I'm not sure the world needs politicians "solving" problems nobody understands. Quite likely a case of "Now you have two Problems"

      You're biased against laws/regulations and can't see the real problem in front of you. You can't see that this law is actually sane when compared to the **currently** insane practices of manufacturers.

    4. Re:Have they really thought this through? by houghi · · Score: 1

      1) The fact that you buy a toothbrush that is connected to the Internet, of all things, might be the issue here.
      2) The fact that you buy a TV that is connected to the Internet, of all things, might be the issue here.

      The "problem" that was not there was "solved" by connecting it to the Internet. It mode things with "no problems" go to "one problem".
      The password issue is trying to solve a problem that should not even exist.

      --
      Don't fight for your country, if your country does not fight for you.
    5. Re:Have they really thought this through? by Anonymous Coward · · Score: 0

      1 Still no internet connected toothbrushes at the local grocer (or even pharmacy).

      2 Grandma most likely couldn't set up that Smart TV and password even if it was in English, the latvian thing is stupid

      2a Living in EU and working in the EC, I can promise you that even idiots are not too awfully confused by other languages.

      2b Are you in EU? Then she is used to it. Not? Why the fuck would you get a TV that thinks its in Latvia??? As an ex-californianer i've never had a 'smart device' of ANY sort over the years default to any language other than English, even in San Diego so close to the border.

      2c Every device I've had that DIDN'T default to english (i.e. here in belgium) asked you what language you wanted, then presented a list of languages to allow you to chosoe.

      3. Every device I've EVER HAD that had an internal password (not even recent mind you, dating back to my first wifi router in 2001) has a reset button someplace on it (or in the case of smart phones, a reset process.

      3a. Every one of the dvices I'm talking about also came with an instruction manual with someplace that told you how to reset the device.

    6. Re:Have they really thought this through? by Anonymous Coward · · Score: 0

      Tev tagad parole jamaina!

    7. Re:Have they really thought this through? by Anonymous Coward · · Score: 0

      If the toothbrush needs to be connected to internet, there must be some way to configure it.

      The TV can be reset to factory defaults and a new password can be generated at that time. The only reason the TV would need a password is if it worked as a server and for "parental control". Not many TVs work as a server to the internet, so login in to the TV from the internet should not be possible. If it is then it the password can't be something "only" the manufacturer knows and has set as "admin" or "root" or "password" or something stupid like that.

      I understand the problem and this solution, which is good, but hard to enforce by a single state.

    8. Re:Have they really thought this through? by nine-times · · Score: 1

      She pushes random buttons until the weird prompt(s) go away. Congratulations grandma, you've set an unknown password and effectively bricked your new TV. Who is going to unbrick it? How?

      First, devices often have some method to reset the password. They hold a button a 'reset' button while they reboot the device, and the password gets reset. So the TV doesn't need to be bricked.

      Second, when talking about the various dangers of internet connected devices, it's this kind of unknowing user that make this default password such a big problem. A lot of grandmothers (and other people), instead of pressing random buttons to get past the prompts, will just leave all the default settings, leaving their devices completely exposed. It's often going to be better that they lock themselves in than if they leave the device completely open.

    9. Re:Have they really thought this through? by darkain · · Score: 1

      The problem with "decent default passwords", is that it turns out that far too often its literally just something like HASH(MAC_ADDRESS) - so it is easy to figure out just from connecting to the device itself. They practically TELL you their default password. This has been done to keep the firmware flashing process "easy", since it is the same for all devices, instead of programmatically generating that one little string on a per-flash basis.

    10. Re:Have they really thought this through? by Anonymous Coward · · Score: 0

      The fact that you buy a TV that is connected to the Internet, of all things, might be the issue here.

      Yeah, try not doing that. It's not impossible, but it's more and more difficult as time goes by.

    11. Re:Have they really thought this through? by vtcodger · · Score: 1

      No, I'm actually in favor of regulation. The problem is your inability to see the difference between sensible regulation and compounding problems that exist because of crackpot engineering and general lunacy. In point of fact internet connected toothbrushes are an example of a device that is useful only for a small number (quite possibly zero) of users. But incredibly they do exist and marketplaces do not seem to be very good at efficiently consigning such products to oblivion. Also there is the inconvenient problem that passwords (good or bad) don't actually work very well.for most purposes. We use them because they are pretty much all we have. They really are not especially good at providing security and they are a major impediment to usability. And finally, the idea of household networks that require administration skills is amusing, but kind of absurd. Neither typical users nor manufacturers want them. They will, trust me on this, find a zillion ways to bypass/obviate the security unless it is unobtrusive. But the IT industry has no clue how to do unobtrusive security, much less effective unobtrusive security. It may well not even be possible.

      --
      You can't see ANYTHING from a car, You've got to get out of the goddamned contraption and walk...Edward Abbey
    12. Re:Have they really thought this through? by Anonymous Coward · · Score: 0

      OK. I drop my toothbrush and it breaks. So I go to the store and find all six of the toothbrushes I can choose from are internet connected. I pick one, go home, plug it in. Now I enter a new password. How do I do that? It's a toothbrush.

      ------

      My (conceptual and imaginary) grandmother buys a new "smart" TV. (Seriously, "They" apparently don't make dumb TVs any more). She plugs it in getting many of the connections right. It asks (in colloquial Latvian because it's a bit confused about where it is) for a new password. She at least has an input device-- the remote. She pushes random buttons until the weird prompt(s) go away. Congratulations grandma, you've set an unknown password and effectively bricked your new TV. Who is going to unbrick it? How?

      -----

      I'm not sure the world needs politicians "solving" problems nobody understands. Quite likely a case of "Now you have two Problems"

      More like a case of "you didn't actually read the article." The regulation only applies to devices that require you to sign in. Your toothbrush wouldn't be affected and most likely your grandmother's smart TV wouldn't either since they don't typically require you to sign in to actually watch TV or even access most of the functionality. I've never had to use a password to use any of the smart TV apps that didn't already require one as part of the service.

      Furthermore, the regulation only requires manufacturers to "equip the device with a reasonable security feature or features that are appropriate to the nature and function of the device." Once again, this would not apply to your toothbrush or any other hypothetical device that would not normally need a login to use.

    13. Re:Have they really thought this through? by vtcodger · · Score: 2

      "If the toothbrush needs to be connected to internet, there must be some way to configure it."

      The issue of an internet connected toothbrush is kind of interesting. I picked it because it's a blatantly nutty idea. But Google assures me that such things do exist. How DO you configure it? The obvious notion would seem to be via a web server on port 80. But that implies that the crazy thing can get to the network -- which suggests that it either has an RJ45 network connector (who has network ports in their bathroom? Not me). Or (scarier) goes looking for a non-password protected Wi-Fi network. And even if it can get a network IP address via DHCP (What if there is no DHCP server running?) How do I find what IP address it got. UPNP? Bonjour, clairvoyance? I'd probably use arp-scan, but I think that's a bit of a stretch for a typical user. What if it has hooked up to my neighbor's Wi-Fi network?

      Maybe it's got a USB port? What class of USB device does it claim to be that will allow me to get help instructions and configure the device from a terminal or browser? I wouldn't be surprised that there is such a class, but I don't know off hand what it would be.

      Anyway, configuring the device likely is possible, but what's the likelihood that an average user can figure it out? Or has the the patience even if they have the brains?

      So, my guess is that the devices will end up mostly running via some weird kludge with no actual security whatsoever. They'll have great passwords if that's what the law dictates, but the passwords won't be used/needed for anything.

      --
      You can't see ANYTHING from a car, You've got to get out of the goddamned contraption and walk...Edward Abbey
    14. Re:Have they really thought this through? by Agripa · · Score: 1

      There is the possibility of unique passwords being issued with each device.

      So instead of the devices being compromised one by one, they will all be compromised at once after the manufacturer is compromised.

  11. Re:Honeypot is illegal in California? by Anonymous Coward · · Score: 0

    If you keep actual personal information in your honeypot, then i guess yes, but this bill does not seem to be about that.

    It's about manufacturer putting some sort of ID or serial based password for each manufactured device instead of "password" by default or making sure user changes it on first start. If you manufacture honeypot devices, then user just changes the password to something easy to guess.

  12. Jesus Christ by Anonymous Coward · · Score: 1

    Does everyone in the tech industry have to use vegan references in an analogy that is completely preposterous?

    The better analogy would be like classifying all driver's licenses as aviation licenses. Then you'll have millions of untrained, and uneducated pilots flying airplanes.

    The moral of the story; A vast majority of people who use a network, should probably not be allowed to use the network or internet without a personal administrator. If you are going to allow all people to use the internet without IT supervision, than deal with the consequences of delinquency on the internet. You can't fix it. No sense in bitching about it.

  13. "The key to dieting is eating the correct amount." by Anonymous Coward · · Score: 0

    Dieting is keeping check on what you eat. If you want to gain weight you eat more if you want to lose weight you eat less (than you burn).

    If people are going to use analogies they should be sure that they understand the thing they use as an analogy.
     

  14. Dieting is NOT "eating less". That makes you fat! by Anonymous Coward · · Score: 0

    The problem is that fat people have a massive Leptin resistance. Meaning they are numb to their body's signal that they are full.
    Which is caused by certain gut bacteria flooding the body with it.
    Which, itself, is caused by there being so damn many of those bacteria.
    And those are there, because they feed on pure carbs. Not whole natural cells, like any plant, but extracted, processed, and condensed carbs, without the required accompanying ingredients, that keep the bacteria from causing an inflammation.
    (So carbs are not bad per se. It's the imbalance and denaturation. Any other imbalance [like pure salt] or denaturation [like denatured dairy] would be just as bad.)

    When you eat an actually balanced and natural diet, all that happens with high-energy food like fat, is that you are full much quicker. And you can still stuff yourself with low-energy food to the max, and not get fat.
    So you simply cannot eat too much, since you will not want to.
    The will to eat more than you need, is the illness. And no amount of "willpower" (read: harmful ignorance of the body's signals to freakin change!) is going to fix that. You will only become a stupid ignorant masochist. Only banning those highly purified things, that are essentially drugs, from your life, can.

  15. White boxes by The+Cynical+Critic · · Score: 4, Interesting

    I'm not sure this is going to cause anything other than a bunch of insecure devices disappearing off store shelves in California specifically. Don't get me wrong, this is progress, but it's not the kind of really fast progress that is actually needed seeing how really badly secured devices being sold today are going to be causing us issues decades from now.

    The fundamental issue is that most IOT gear is really just really cheaply made and designed white box devices from obscure Chinese vendors consumers have never heard of and which the companies under whose name the devices are sold to consumers just order them from the vendor with their name and logos slapped on at the vendor's factory. Until you can force the white box vendors to properly secure their cheaply made and designed hardware, we're just not going to be able to make a dent in the problem.

    --
    "Why should I want to make anything up? Life's bad enough as it is without wanting to invent any more of it."
    1. Re:White boxes by Anonymous Coward · · Score: 0

      Sadly, California is too big of a market to ignore. Most of the major manufacturers will add the "California compliant" functionality to their product, or make a special one off "California Edition" product for higher price tag products.

      But, yeah, this probably will not stop people importing Chinese white labeled IoT crap products with no security on them into California or anywhere else. They'll just keep changing the brand names and model numbers if the regulators catch on.

    2. Re:White boxes by The+Cynical+Critic · · Score: 2

      Considering how the reason why companies that use white box hardware is that said products cost them nothing or next to nothing to develop I'm not so sure they will start limiting themselves to properly secured white box hardware.

      When car makers make sure all of their U.S cars are compliant with the more stringent California Air Resource Board standards they've spend billions developing them and obviously need to sell a lot of them to recoup the development costs. Companies that sell white box hardware with just their logo slapped on have no sunk capital that needs to be recouped and can easily afford to ignore California, particularly when the market for that specific product is pretty much the rest of the world.

      --
      "Why should I want to make anything up? Life's bad enough as it is without wanting to invent any more of it."
    3. Re:White boxes by Anonymous Coward · · Score: 0

      Get real. This will fix the refrigerators, etc. that come with shitty passwords. Samsung is not going to stop selling smart fridges and TVs into California.

    4. Re:White boxes by DerekLyons · · Score: 1

      I'm not sure this is going to cause anything other than a bunch of insecure devices disappearing off store shelves in California specifically.

      California is a huge segment of the US market - and not one that a seller can ignore and remain competitive.
       

      Until you can force the white box vendors to properly secure their cheaply made and designed hardware, we're just not going to be able to make a dent in the problem.

      The easiest way to do that is to make their buyers care about security specs. The easiest way to do that is to regulate the sale of such items. It isn't going to happen by sitting around making sophomoric (and ignorant) statements.

  16. stereotypical government by mailman42 · · Score: 1

    typical non-thinking government. create abstract rules/laws, that actually do nothing or more harm

    1. Re:stereotypical government by Anonymous Coward · · Score: 0

      Typical non-thinking anti-government knee-jerking. How would this do any harm? Anything that improves password discipline, even a little bit, is a good thing. I'm sure nobody has the illusion that this will fix all security issues, but every little step helps.

  17. Caifornia takes the super liberal thing too far. by TomBauserman · · Score: 1

    You can't "law" stupid away. Some things you just have to let them work themselves out. If you have a brand of devices that are constantly getting compromised. People will stop buying them. i

  18. Self-breaking by Anonymous Coward · · Score: 0

    How about internet connected devices are required to have a built-in (and network assisted, since by definition the network is available when this matters) password cracking subsystem. When the subsystem guesses your password, you are required to change your password.

    And, for good measure, when a password is reset due to a self-breaking, the broken password is added to the networked repository of passwords-to-check-first.

  19. IoT devices should each get by FudRucker · · Score: 1

    a unique password made by a password generator at the time of programming or when they load the software/firmware on it, and a label printed on a card or tag tied or taped on to the device included with that password during packaging

    --
    Politics is Treachery, Religion is Brainwashing
  20. I have better suggestion by Anonymous Coward · · Score: 0

    Instead of doing dumb laws that no one could implement realistically, how about you put a ban on routers who allow NAT/port forward?!? This way, all those IoT devices would work in LAN and if you so damn want to , i don't know, control your lights from your workplace to feel good about yourself, just use a VPN (OpenVPN is a decent free alternative), connect to your local network and do w/e the fuck you wanted to do in the first place. This way your devices will never be exposed to outside threads. There, boom, problem solved.

    The actual issue is that it's way too easy to open router ports. And a lot of people abuse this right.

    Even if you are on a dynamic IP you can use stuff like DynDNS to have a single endpoint to your home network.

    Once that's done, your bloody IoT password could be randomized 4 zeroes or some shit.

  21. Re:Caifornia takes the super liberal thing too far by Anonymous Coward · · Score: 0

    You can't "law" stupid away. Some things you just have to let them work themselves out. If you have a brand of devices that are constantly getting compromised. People will stop buying them. i

    "Voting with your dollars" doesn't always work.
    (IMO it rarely works. But that's another debate)

  22. Strict liability and products by sjbe · · Score: 5, Insightful

    You think "security" is something that can be "built in." Security in software development is a mindset.

    A mindset in a software developers head is a useless thing to an end user. It might start there but it has to actually become something more than that. Ultimately security has to manifest itself in products (software and hardware) and processes to use those products. A developer's mindset will not keep a network or device or data safe any more than and engineer thinking about how to stop a car will actually cause one to halt. So yes, security ultimately has to be built into whatever device(s) and software you are using.

    My idea is, everytime a vendor has a security issue on their device, I want a refund.

    Then you would have no devices because it's impossible to prove that non trivial devices and software have no security issues. Nobody could ship a product and be sure there was no security issue they missed. It is arguably reasonable however to apply strict product liability laws to software and to hold companies financially accountable for damages. Current application of product liability laws routinely provide software makers too much wiggle room to avoid responsibility for their failures, particularly with regard to security.

  23. unfortunate by Anonymous Coward · · Score: 0

    Unfortunate the California doesn't ban California. That would be progress.

  24. Three squares a day is BS by sjbe · · Score: 0

    So, start with eathing three good, full meals. That definitily helps to quench the snack attacks.

    I'm guessing you've never really actually tried to lose weight. That is definitively NOT the advice you will receive from experts on the subject. The three squares a day idea does not derive from any actual evidence about its utility for weight maintenance or health. In fact if most people tried just eating three meals a day and not snacking with an eye towards weight control then they will very likely fail to maintain that regimen for any significant length of time. This has been demonstrated time and again in research on the topic.

  25. Better ban stupid programmers by Anonymous Coward · · Score: 0

    Also while they are working at that, why not ban also stupid users, who don't change their default password.

  26. Re:Caifornia takes the super liberal thing too far by Anonymous Coward · · Score: 0

    Oh damn, he got hacked in the beginning of a sentense. Stupid default router admin password.

  27. California...really? by yodleboy · · Score: 1

    Is this the most pressing need? CA is a state full of idealists that "fix" things, then move on to the next shiny issue. Five years later, they fix the "fix" that never worked. All the while bleeding money.

  28. Penalties for negligent companies by sjbe · · Score: 2

    You can't "law" stupid away.

    No but you can make penalties for it for companies that do stupid things. Companies are supposed to be able to hire smart people to figure this stuff out and if they fail to do that there should be consequences with teeth.

    Some things you just have to let them work themselves out.

    Product liability isn't one of them. Neither is negligence.

    If you have a brand of devices that are constantly getting compromised. People will stop buying them.

    HAHAHAHAHAHAAAA!!!! I refer you to Microsoft Windows, Adobe Flash, and Microsoft Office. Not to mention countless shitty routers and IOT devices that get pnwned every day. People buy things all the time with vast security problems that are well known about prior to purchase. Your argument is not supported by facts.

    1. Re:Penalties for negligent companies by Anonymous Coward · · Score: 0

      >No but you can make penalties for it for companies that do stupid thing

      Sounds like California doesn't need any more import companies. No problem, you don't need any jobs.

      >Product liability isn't one of them. Neither is negligence.

      Sorry, did a spam kill your cat?

  29. Re: It should be by Anonymous Coward · · Score: 0

    Like requiring unlimited full purchase price refunds wouldnâ(TM)t be a nuclear strike on any industry.

  30. Solution: Ban the 1% of most popular passwords. by Anonymous Coward · · Score: 0

    Modern systems already contain functionality to allow any too obvious passwords. It would not be hard, to grab one of those "most popular passwords" lists, and block any passwords in there. Frankly, I'm surprised that isn't already built into modern GNU.

    1. Re:Solution: Ban the 1% of most popular passwords. by Anonymous Coward · · Score: 0

      As soon as you block the say, 100 most popular passwords, you just created a new list of the 100 most popular passwords.

  31. from the show-me-your-password dept. by jerralb · · Score: 1

    California Government: I need to see your password in order to determine if it's secure. (facepalm)

  32. Instead, legislate fine them for security lapses by MobyDisk · · Score: 2

    In general, legislating one particular best practice does not fix an industry. And there are better ways than writing laws. Some ideas:

    • * Require that government entities only purchase products from companies that have not had certain categories of security lapses in the last 6 months
    • * Require that government entities only purchase products from companies that have a policy of fixing security bugs within X amount of time
    • * Provide funding to startup a commercial product security certification organization, similar to what underwriters laboratory (UL) does for safety.
    • * Setup liability law so that any owner of a device that doesn't follow industry best practices can be sued by an owner of that product.

    Any of the above would mean that, for example, California government would no longer buy Western Digital hard drives. These suggestions intentionally do not state what the specific best practices is, and other than the last one they don't require laws, which are slow to change. The specific practices can be defined by some of the many organizations that already do that. Ex: OWASP top 10, static analysis, pen testing, etc. This is similar to what the FDA did with medical devices, to make manufacturers stop doing idiotic things like using unauthenticated Wifi on insulin pumps so hackers could remotely kill people.

  33. Re:Caifornia takes the super liberal thing too far by TomBauserman · · Score: 1

    I would upvote you. But you're a coward.

  34. Re:It should be by nine-times · · Score: 2

    How does having a secure operating system help when the web frontend developer doesn't understand how to correctly validate passwords.

    Well the IoT manufacturer also has to do their job in building whatever web interface they build, but it certainly helps to start from a secure OS.

    While having the source code available is helpful to see if there are security issues, that doesn't mean they will be found. Open source doesn't provide for greater security though.

    Well it doesn't inherently completely make for better security. It does have some advantages, though. There's the obvious fact that there are generally more eyes on an open source project, so security problems may be more likely to be noticed. Also, frankly, security is hard to do well, and having a bunch of random developers coming up with their own solution will result in a lot of those developers doing it wrong. If you can create a coherent security standard that everyone can work from, then a lot of people have a vested interest in doing it well, and it'll probably be done well.

    Obviously there are also downsides. The fact that there are a lot of eyes on the source also might make it easier for someone malicious to find an opening. Also, everyone standardizing on one security standard (or one OS) makes a monoculture. It means there's one big target to exploit, and if you can exploit it, you can get access to pretty much everything.

    On the whole, I think it is smart for IoT manufacturers to use an established open source OS, both to save themselves money and to start from a point of relative security... but I think they already do that. AFAIK, a lot of those things are somehow built on Linux or a BSD. I don't think we need a singe OS, but I do think we need to figure out some security standards that establish what constitutes an acceptable level of security for an internet connected device.

    I also think that, for consumer protection reasons, there should be some kind of push to open source the software computerized devices and appliances. Manufacturers can too easily stop updating things and drop support, leaving the people who owned it with no options but to replace the device.

  35. Re:It should be by mjwx · · Score: 3, Informative

    all building a single OS for IoT with security built in

    You think "security" is something that can be "built in." Security in software development is a mindset. How does having a secure operating system help when the web frontend developer doesn't understand how to correctly validate passwords.

    Security in everything is a mindset... However a good mindset on it's own is useless. You need to give the user the tools as well.

    What we have needed for years in connected home appliances is for the first configuration screen to be "Change this default password before the device becomes usable". Laws here in the UK have meant that ISP's aren't permitted to hand out devices with generic or default passwords, so every router you get has a sticker on it with your individual password.

    --
    Calling someone a "hater" only means you can not rationally rebut their argument.
  36. Sounds like a rush job to me. by Anonymous Coward · · Score: 0

    So the details are vague? Morons. If they had any sense, we'd know already if "bad passwords" were defined by a lack of entropy (smart) or a lack of uppercase letters, numbers and symbols (dumb). The lack of any further information suggests California will see the latter, not the former, become law -- especially if the intel community has anything to do with it. Forcing people to adopt the illusion of a strong password would be much more effective than proper password education.

    Meanwhile, I'll continue turning my friends and family onto Diceware. It's worked very well so far, most people find it fun.

  37. Already done. It's called Adderall, Xanax, etc. by Anonymous Coward · · Score: 0

    I'm told that the big drug dealers are already pushing doctors so hard to sell them, that half the US students pop them like candy. (And the other half either soon will, or already takes others that are basically the same thing but illegal for "some reason".)

    And given that the US does not have a government, but a council by the corporate oligarchy, which writes all of their laws... as soon as it becomes necessary for profit reasons, it will become a law.

  38. Re:It should be by Wycliffe · · Score: 1

    My idea is, everytime a vendor has a security issue on their device, I want a refund. They sold me a defective device with defective software. We need to stop calling software buggy and call it what it really is, DEFECTIVE.

    Everything internet connected should be sold with a lifespan and support for X number of years (and labeled as such on the package). They do this with carbon monoxide detectors. After 7 years, they turn off and won't work anymore and just beep constantly. This is safety feature. IOT devices should probably come with the same thing. After they stop receiving patches, they should stop connecting to the internet. This would be a safety feature not only for the purchaser but to protect the rest of the internet too. (On a somewhat unrelated note, DRM "purchases" should also be clearly labeled with an expiration date thru which the company guarantees your ability to play that song/movie)

    As far as a bug being a defect, bug free software doesn't exist. For that matter, defect free anything doesn't really exist. We already have a system in place for unknown problems that are discovered after the fact. The products are either recalled and repaired or recalled and replaced depending on what the defect is and how hard it is to fix it. Software shouldn't be treated any different than car seats, airbags, or anything else where defects are sometimes discovered after the fact. With software, it should be easier as in most cases it can be remotely fixed without actually having to send the devices in to be repaired.

  39. Nanny-state by DaMattster · · Score: 1

    California is really becoming a nanny-state now. Laws shouldn't be passed to protect people from stupidity. The only protection against stupidity is education. People should take time to learn a thing or two.

    1. Re:Nanny-state by Gilgaron · · Score: 1

      In this case the idea is to stop people buying IoT from breaking the internet for everyone, so it is more like passing a law saying you can't sell tires that will tear up the roads.

    2. Re:Nanny-state by omnichad · · Score: 1

      Laws shouldn't be passed to protect people from stupidity.

      Nobody can be an expert on everything. Especially without awareness that there are important things that they need to know. You can't go out and learn what you don't know you need to know.

      There's really no reason or defense for the insane defaults we have now. Cars don't default to having the airbags disabled. Refrigerators don't default to temperatures outside of the food safety zone.

  40. Re:It should be by omnichad · · Score: 2

    main software developers all building a single OS for IoT with security built in

    A software monoculture is great for security. Much more efficient to take down the entire globe at once when a flaw is discovered.

  41. What's next? Shoestring knots? by biggaijin · · Score: 1

    The governor and state legislature in California are doing their best to advance the nanny state to protect all of us. Just recently, they passed a state law that schools could not open before 8:30 am so that the students would get enough sleep. And, of course, the plastic bag and plastic straw bans are spreading across California like a fungus. Now they are passing a law to force us to lock up our wireless routers properly. Next will be a law prescribing a particular method of shoe-tying so that none of us will trip on our laces and get a boo-boo.

  42. CA password by Anonymous Coward · · Score: 0

    SO I a guess all the important issues in California are fix they can now worry about my NEST password.

  43. Re:It should be by jittles · · Score: 1

    My idea is, everytime a vendor has a security issue on their device, I want a refund. They sold me a defective device with defective software. We need to stop calling software buggy and call it what it really is, DEFECTIVE.

    Do you happen to own a buggy whip factory? Cause your proposal would result in a complete backslide in technology. Humans err. If they did not intentionally create a defect and are willing to help you get it fixed, why do you think you ought to get a refund? Did you get zero utility out of the software before a defect was found?

  44. Re:Instead, legislate fine them for security lapse by omnichad · · Score: 1

    Provide funding to startup a commercial product security certification organization, similar to what underwriters laboratory (UL) [wikipedia.org] does for safety.

    You know what underwriters do? They back insurance risks. Fires are very expensive. There is no financial incentive behind consumer electronics security like there is for insurance agencies to prevent fires.

  45. Re:It should be by Anonymous Coward · · Score: 0

    How does having a secure operating system help when the web frontend developer doesn't understand how to correctly validate passwords.

    You give that front-end dev a API which is easier to use than rolling their own system (laziness always wins), that is secure (handles salting, peppering, etc. for them).

  46. Re:Honeypot is illegal in California? by Anonymous Coward · · Score: 0

    So I want to set up a honeypot to trap intruders, with 1234 as password.

    The state of California is telling me that I can't do that?

    No, but apparently actually reading (TFA or even just TFS) is illegal in your state. This is talking about DEFAULT passwords...you know, the one that comes on the device when you first get it. The proposed law says absolutely nothing about the strength of passwords you can set on your own.

  47. Re:It should be by Anonymous Coward · · Score: 0

    LOL stop.

  48. The bill should not be either-or... by mark-t · · Score: 1

    It should require every device that has is connected to have a unique default password, and that password should be printed on a sticker that is afixed to the device in a location that is consumer-accessible, but does not affect functionality or aesthetic appeal (ie, on the bottom or back of the device) if possible, or if and only if the device has no such convenient location, on a similarly sized piece of paper that is packaged with the device.

  49. Idiocracy by Zorro · · Score: 1

    This is how Idiocracy becomes real.

    By preventing the stupid from hurting themselves.

    1. Re:Idiocracy by Anonymous Coward · · Score: 0

      Allowing weak passwords does not help the stupid eliminate themselves fast enough to prevent children, so it has no impact on the Idiocracy premise.

  50. I prefer my cameras to have no password by mea2214 · · Score: 1

    My cameras are on an isolated LAN that is air gapped. Since all IP cameras require credentials I use the same username and password for each one. That's only one thing to remember 18 months from now when I might need to mess with one. I don't want a different password that I have to keep track of for each camera. There are many layers to security and user credentials are only one. We don't need legislatures making things more complicated. KISS is the best security.

    1. Re:I prefer my cameras to have no password by Anonymous Coward · · Score: 0

      My cameras are on an isolated LAN that is air gapped.

      So were the Iranian centrifuges, and Stuxnet managed to jump that.

  51. Re:Instead, legislate fine them for security lapse by nickersonm · · Score: 2

    • * Require that government entities only purchase products from companies that have not had certain categories of security lapses in the last 6 months
    • * Require that government entities only purchase products from companies that have a policy of fixing security bugs within X amount of time

    Stuff like this sounds great in practice, and even makes a good amount of sense - why not use capitalism itself to promote desired behavior? But these kind of restrictions on government purchasing are why government pays twice as much to make what should be easy purchases. "Approved vendors", "preferred suppliers", and "government rates" because it takes so much paperwork. This also excludes small companies who don't have staff dedicated to filling out government paperwork.

  52. Does California Govt abide by this already? by Anonymous Coward · · Score: 0

    The California Government doesn't do this, they should start with themselves first, and all the county and city governments also.

    Call the DMV and they only verify you with common, public information.

    Isn't it freedom of speech for all my passwords to be 'password'?

  53. Forgot what serial means? by raymorris · · Score: 1

    Did you forget what the word "serial" means?

  54. 2 factor authentication by joe_frisch · · Score: 1

    Because we want to be sure that we know what person the surveillance devices are watching.

    The real question is why we need so many miscelaneous devices connected to the internet with with anything more than a one-way data link.

  55. Or... by dkman · · Score: 1

    Just make the default password some ugly long gibberish and the users are likely to change it to their dog's name just because they don't want to type that monstrosity again.

    --
    I refuse to sign
  56. Re:It should be by Anonymous Coward · · Score: 0

    Did the driver get use from the vehicle before it burst into flame and killed all of the occupants? I guess the owner has no room to complain. Bugs and security issues will arise. It's how the manufacture deals with the flaws, not if there are flaws. Perfect is the enemy of good, but much software is down right bad. Lets have internal services listen on the WAN with a static password with root access and NEVER gets fixed.

    The obvious, but difficult to define, solution is to require the manufacturers to fix security issues in a practical "timely" fashion.

  57. Re:Caifornia takes the super liberal thing too far by Anonymous Coward · · Score: 0

    Ivory tower theory is disconnected from reality. Uninformed people looking for the cheapest product will not stop buying. We don't need laws making things illegal, we need lemon laws allowing customers monetary recourse.

  58. Re:It should be by OrangeTide · · Score: 2

    You think "security" is something that can be "built in." Security in software development is a mindset.

    You mean I can't just order my embedded software from a Chinese menu and check the box for "Yes, security please" ?

    My crash course in security paired down to what I could reasonably fit into a post:

    The process of threat modeling is a formal analysis of the security of a system. One easy to remember process is to use the mnemonic STRIDE - Spoofing, Tampering, Repudiation (sharing of access tokens or accounts between users, man-in-the-middle, social engineering, phishing scams, etc), Information disclosure, Denial of service, Elevation of privilege.

    You can begin to build a picture of your threat models with a tool like SeaMonster. That's only one example there are many other tools available of course, such as Microsoft's SDL Threat Modeling Tool.

    A formal process is pretty important, even if it's as basic as a spreadsheet that lists the threats you came up with. Reviewing the list, prioritizing it, and determining a schedule for addressing threats is better than an ad hoc hand waive to developers a week before release. ("Guys, ya, um I'm going to need you to make it secure."). An iterative process for security that begins the same day you start architectural talks is the better way to approach the problem.

    --
    “Common sense is not so common.” — Voltaire
  59. Re:It should be by rogoshen1 · · Score: 1

    that sounds suspiciously like the windows 10 update mindset, and it's a fiasco.

    If you buy hardware, it is yours, and you should retain ultimate control over it.

    If i'm a dummy and don't update my webcam's password, or refuse to heed the warnings that its security has been compromised -- well guess what? That's my fault, and no on elses.

  60. Re:Instead, legislate fine them for security lapse by MobyDisk · · Score: 1

    You know what underwriters do? They back insurance risks. Fires are very expensive.

    That's what UL was for back in the 1800s. Things do a lot more than fire safety these days.

    There is no financial incentive behind consumer electronics security like there is for insurance agencies to prevent fires.

    That's why all of my options included making security a liability for those companies. My last bullet point was explicit financial liability. The other options involved liability of the form "This is a liability because a large organization won't buy my product."

  61. Re:Instead, legislate fine them for security lapse by MobyDisk · · Score: 1

    ...pays twice as much...

    Yes, security costs money. And auditing companies to make sure they comply costs money. Today people demand the cheapest parts possible, so companies don't bother with proper security. If we want security, we have to pay for it. If I had the choice between a Western Digital Passport drive (regarding the story earlier today), and another vendor that had real security but cost twice as much, I would take the one with security. And if California wants secure devices, they should too. Hopefully, we can make a security mindset infectious and it is just the default behavior.

    "Approved vendors", "preferred suppliers", and "government rates" because it takes so much paperwork.

    Those things already exist so California is already paying for it. No new costs here.

    This also excludes small companies who don't have staff dedicated to filling out government paperwork.

    It definitely does not. I personally know several 1 to 10-person companies who have gone through that paperwork. Going back to your first point about government contracts being more expensive, this is why it is worth it for a small company to go through that paperwork.

  62. Re: Caifornia takes the super liberal thing too fa by KingAlanI · · Score: 1

    When those security holes are exploited to create botnets that then attack a 3rd party it's not a personal freedom to be stupid issue. Antivaxxers threatening herd immunity is a rather direct analogy.

    --
    I listen to both RIAA and non-RIAA stuff if I like the music, tangential business/politics nonwithstanding.
  63. I assure you my company will NOT comply by Anonymous Coward · · Score: 0

    Fuck California and the socialist hell hole it is. I'm pro-security- but it's not up to the government to tell us how to design shit. If customers want security let them speak with there pocket book. If people actually care about security they will seek out our products over the shit most companies put on offer. We probably aren't compliant actually with one of our security-conscious products- but anybody following the directions isn't at risk of anything. The device itself is well designed from a security perspective and changing the design would have significant consequences to the price- needlessly.

  64. Re:It should be by Anonymous Coward · · Score: 0

    Another bull shit socialist law my company refuses to comply with. Fuck the UK. Fuck California. It's not that I think this is a bad practice. It's just that such laws are an abuse of power. Governments should not be doing shit like this in violation of fundamental freedoms. I support free markets and governments tend to cause markets that would otherwise be free markets to get really fucked up. If people want security like me they can purchase the products that don't suck and help fund the projects that lead to products that don't suck. I've funded to the tune of $60,000 of a single critical free software project over the past couple years. Freedom and security don't require government. All it requires is people caring. If you don't care about your security you have no right to bitch or to demand others pay [via government violence] the costs of investigating those who hurt you.

  65. Re:It should be by Darinbob · · Score: 1

    A single OS for IoT is ridiculous. IoT is not like a PC or smartphone where one size fits almost everyone. Every IoT device is unique with unique goals and purposes. What is appropriate for a sensor device that runs unattended for twenty years in the field on a single battery should not have to have the same OS as a consumer IoT device that tells you if your refrigerator is on or not.

  66. Re:It should be by Darinbob · · Score: 1

    This depends upon what the security is for. Validating passwords sounds like an application front end, most IoT devices usually only talk to other devices. So you need to make sure your networking security is good so that you can't be spoofed, and you can verify certificates from neighboring devices or a back office (pre-shared keys is a recipe for disaster). Then you want security so that your device can't be cloned more cheaply by someone else, so lock down the firmware and encrypt it, etc.

    Then there are the generic security issues, not related to crypto or authentication. Such as buffer overflows, allowing a drive-by attacker to reboot your device by exploiting known crashes, etc.

  67. Re:It should be by Darinbob · · Score: 1

    Is the web interface on the actual device, or in the back office? I've worked on devices that don't have room to fit even the simplest web interface and with no convenient way to talk to them without specialized equipment. From the devices I've worked on, the security doesn't start in the OS, most small operating systems don't come with security built in and when they do they're inappropriate for your product (ie, you'll rarely find a PKI solution). The OS has no idea what you need as security, what protocols you will be using, how your hardware crypto worksm etc.

    Maybe people need to stop thinking of Linux as a "tiny" OS that can be a starting point, when it is gargantuan compared to most small embedded systems. Or maybe people are thinking like "iOS" which has more application framework than actual operating system.

  68. Re:It should be by Darinbob · · Score: 1

    This is fine if a person's freedoms don't interfere with other people's freedoms. Often there's a collision; once two people meet the freedoms they had as isolated individuals are now diminished (either through physical intimidation by one party or a set of rules and guidelines set up by a government). This is not socialism except by the distorted rewriting of the dictionary by the alt-right. Even many rabid libertarians I know agree that government has a responsibility here.

    A government clearly has a vested interest in protecting customers from badly built products, including wifi routers. Not every customer should be required to be a guru or to fully educate yourself. The end customer is freely allowed to ignore safety features if they want (but beware of lawsuits if someone else gets hurt).

  69. limit it to network connected devices. by Anonymous Coward · · Score: 0

    I say this because I would love incentives for companies to not make gadgets network connected. Some do not need to be. This goes back to how frustrated I get that my microwave insists I enter a date after a power outage. Time is fine. Its a convenient area for a clock to be. There is no reason it needs to know the date and even less of a reason it ever needs to connect to a network.

  70. Re: How will this law be enforced? by Darinbob · · Score: 1

    There's a new breed of libertarian that thinks freedom is about letting a corporation do whatever it wants to do. Apparently even citizens believe that corporations are people too.

  71. Re:It should be by Wycliffe · · Score: 1

    If i'm a dummy and don't update my webcam's password, or refuse to heed the warnings that its security has been compromised -- well guess what? That's my fault, and no on elses.

    That's fine but ISPs should also start terminating connections of people whose devices are unknowing participants of botnets.
    The other problem is that you're assuming there are updates. What happens when that webcam has a security flaw and the company doesn't fix its firmware (or even has the ability to do so). Changing the default password isn't the only problem, it is the idea that the manufacturer's responsibility ends as soon as money is exchanged. There should probably some sort of contract with all but the cheapest devices that the device will get security updates for X number of years. Many cell phones never get a single update after they are sold and cheaper consumer devices get even fewer updates if any.

  72. Democrats running CA have raw sewage... by Anonymous Coward · · Score: 0

    in the streets of their big cities, used needles too, and the resulting Hep-A debacles. They have taken the "golden state" and made it the state with the highest poverty rates, highest income inequality, and with nearly the worst K through 12 education system - but HEY! they want to write laws about the features of software produced by private companies and sold to free individuals.

    [sigh]

    These people have no priorities and no common sense, and they despise the free markets.

  73. Re:It should be by rpstrong · · Score: 1

    Many cell phones never get a single update after they are sold and cheaper consumer devices get even fewer updates if any.

    How does a cheaper device get fewer than zero updates? Do they revert to an earlier version?

  74. Re:Honeypot is illegal in California? by rpstrong · · Score: 1

    The intent of the law is to make your device more secure, and the initial password change (or any p/w change) is an ideal time to enforce strong p/w security rules.

    How long before that happens?

          User name: SLIPPERY
          Password: SLOPE

  75. They passed it! by MobyDisk · · Score: 1

    Update from the future: The law passed