Skip to main content

California just became the first state with an Internet of Things cybersecurity law

California Governor Jerry Brown has signed a cybersecurity law covering “smart” devices, making California the first state with such a law. The bill, SB-327, was introduced last year and passed the state senate in late August.

Starting on January 1st, 2020, any manufacturer of a device that connects “directly or indirectly” to the internet must equip it with “reasonable” security features, designed to prevent unauthorized access, modification, or information disclosure. If it can be accessed outside a local area network with a password, it needs to either come with a unique password for each device, or force users to set their own password the first time they connect. That means no more generic default credentials for a hacker to guess.

The bill has been praised as a good first step by some and criticized by others for its vagueness. Cybersecurity expert Robert Graham has been one of its harshest critics. He’s argued that it gets security issues backwards by focusing on adding “good” features instead of removing bad ones that open devices up to attacks. He praised the password requirement, but said it doesn’t cover the whole range of authentication systems that “may or may not be called passwords,” which could still let manufacturers leave the kind of security holes that allowed the devastating Mirai botnet to spread in 2016.

But others, including Harvard University fellow Bruce Schneier, have said that it’s a good start. “It probably doesn’t go far enough — but that’s no reason not to pass it,” he told The Washington Post. While the rule is only state-wide, any device-makers who sell products in California would pass the benefits on to customers elsewhere.

Several Internet of Things-related bills have been introduced in Congress, but none have made it to a vote. The IoT Cybersecurity Improvement Act of 2017 would set minimum security standards for connected devices purchased by the government, but not electronics in general. Taking a separate track, the IoT Consumer TIPS Act of 2017 would direct the Federal Trade Commission to develop educational resources for consumers around connected devices, and the SMART IoT Act would require the Department of Commerce to conduct a study on the state of the industry.



from The Verge - Teches https://ift.tt/2QfN7QU

Comments

Popular posts from this blog

The PlayStation Classic has a secret debug menu that can be reached with specific keyboards

Just a day after the release of the PlayStation Classic , the Retro Gaming Arts YouTube channel has discovered that you can access the emulator’s settings menu by plugging a keyboard into a free USB slot and hitting the Esc key. Doing so reveals a host of settings for the built-in open-source PCSX ReARMed emulator, potentially allowing access to options, including save states, controls, and cheats. The discovery has raised hope that some of the criticisms of the retro console , such as a limited game library and poor image quality, could soon be addressed with third-party modding. In the discovered menus, an option to “Load CD Image” is clearly visible, which suggests it might be possible to load additional games or perhaps just the better-performing 60Hz NTSC variants. An option to enable scanlines, the horizontal lines that allow an LCD screen to emulate the look of a traditional CRT monitor, is also present. Despite the discovery, it’s unlikely that the hardware limitations o

With Toys R Us gone, Amazon wants to send out a holiday toy catalog of its own

Now that Amazon has helped kill off Toys R Us , it wants to borrow the retailer’s iconic print holiday toy catalog . The online behemoth is interested in creating its own print catalog to mail out and also be handed out at Whole Foods (which it owns), according to Bloomberg . Toys R Us was plagued with billions in debt when permanently closed last month — in part because of competition from online stores like Amazon . For many kids, its “Big Book” toy catalog was a staple of fall. The 100-page catalog would arrive near the end of October for kids to look through and create a wishlist before December. Now that the retailer is done, various companies are trying to scoop up the customers that headed to their shelves every December. Party City, for example, will open 50 pop-up toy shops for the holidays. Target will have more store space for toys . It’s just especially amusing that Amazon, having helped kill off these physical retailers, is trying to learn from them to make even mor

Amazon’s plans for a New York office are under new scrutiny

A month ago, when Amazon announced that it would build regional offices in New York and Virginia at great expense to the taxpayers there, I wrote that it had misunderstood the moment : Perhaps the furor over Amazon’s regional offices will blow over. But it’s hard not to feel today as if the company misread the room — overestimating the public’s appetite for a billion-dollar giveaway to one of the world’s biggest companies, and underestimating the public’s ability to raise hell on- and offline. Amazon may yet feel that pain, in the long run. Today, Amazon met the room: 150 protesters who showed up to the first New York City Council hearing about the plan. According to reports from the scene, demonstrators’ concerns start with the $3 billion in incentives that New York plans to give Amazon in exchange for locating there — and, it says, creating 25,000 jobs. Here’s Leticia Miranda in BuzzFeed : ”You’re worth a trillion dollars,” New York City Council Speaker Corey Johnson told the