Tec Nikan
فارسی
Talk to us
All news

UK PSTI Regime Bans Universal Default Passwords Outright

Britain's consumer connectable product rules require unique or user-set passwords, a published route for reporting vulnerabilities, and a stated update period.

PSTIUKIoT securityregulationdefault passwords

The UK's Product Security and Telecommunications Infrastructure regime, in force since April 2024, applies to consumer connectable products — anything that connects to the internet and moves data. Its requirements are short enough to list: universal default passwords are banned, so each product must ship with a unique password or require the user to set one; manufacturers must publish how to report a security issue; and they must state how long the product will receive security updates.

The default password ban is the provision with teeth, and it targets the single mechanism behind most large IoT botnets. Every major botnet of the last decade grew primarily by trying known factory credentials against exposed devices. Removing the shared secret does not make a device secure, but it removes the attack that scales to millions of devices without any per-device work.

The update-period disclosure is the one that changes engineering planning rather than firmware. Publishing a support window turns an internal assumption into a public commitment, and it has to survive vendor SDK end-of-life, staff turnover and the build environment still existing in year eight. Manufacturers selling into the UK, the EU and the US now face three regimes asking for broadly the same three things, which makes designing to the strictest of them the cheaper path.

Source: Finite State

Want to work with us?

Tell us what you're building and we'll help you scope the first deployment.