@fazalmajid@social.vivaldi.net
Post #4210547
2026-07-21 18:50 UTC
@ryanboswell@sfba.social As Schneier points out, California was first:
https://techcrunch.com/2018/10/05/california-passes-law-that-bans-default-passwords-in-connected-devices/
Also, Congress passed the Internet of Things Cybersecurity Improvement Act of 2020 in 2020:
https://www.govinfo.gov/content/pkg/COMPS-15863/pdf/COMPS-15863.pdf
in response to which NIST published SP 800-213 and the NISTIR 8259 series:
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-213.pdf
https://www.nist.gov/itl/applied-cybersecurity/nist-cybersecurity-iot-program/nistir-8259-series
The Biden Administration created the "Cyber Trust Mark", but it's optional labelling, not mandatory, and it is still being set up:
https://www.fcc.gov/CyberTrustMark
Normally devices would have to pass UKCA certification, and the manufacturer would have to attest compliance under penalty of perjury, but what practical enforcement there is, I have no idea. Certification testing was a big business in the UK before Brexit, but many manufacturers just skipped UKCA as the UK was too small a market compared to the EU and CE.
Replies (0)
No replies.