- Written by Lucy Hooker
- BBC News business reporter
image source, Getty Images
Manufacturers will have to follow stricter rules if they want to sell ‘smart’ gadgets in the UK after new laws come into force.
Designed to enhance the security of devices such as baby monitors, TVs, and speakers that are connected to the internet.
These gadgets can pose a risk because cybercriminals use them to hack into your home network and steal your personal data.
The government said the new law must provide “peace of mind” to consumers.
That risk has increased in recent years as more and more web-linked devices, also known as the “Internet of Things,” enter our homes, from gaming consoles to fitness trackers to doorbells to dishwashers.
Previously, manufacturers were required to follow security guidelines, but the new law imposes three new requirements:
- Make sure your password procedures are more secure, such as not leaving manufacturer-set passwords blank and using easy-to-guess choices like “12345” or “admin.”
- Be clear about how to report any “bugs” or security issues you encounter
- Manufacturers and retailers should inform customers how long they will receive support, including software updates, for the devices they purchase.
Failure to meet these minimum requirements, known as the Product Security and Telecommunications Infrastructure (PSTI) regime, can result in fines.
The government said the legislation is a “world-first” that will protect British consumers and businesses and strengthen the UK’s resilience against cybercrime.
According to the Department for Science, Innovation and Technology (DSIT), more than half of UK households now own a smart TV, and more than half have voice assistants such as Alexa installed. It found that each home has an average of nine connected devices.
This includes basic broadband routers, but also toys that link to the web and home appliances that can be controlled remotely, such as radiators, ovens and refrigerators.
But since its introduction, there has also been a surge in reports of hackers taking over and exploiting such devices, sometimes secretly filming and recording them, spying on people, and stealing personal data. .
Sarah Lyons of the National Cyber Security Center said the companies that make the products need to be held accountable.
“Businesses have an important role to play in protecting the public by ensuring that the smart products they manufacture, import or sell are continuously protected from cyber-attacks, and this landmark law “It helps people make informed decisions about the security of the products they buy,” she said.
Ken Munro, a security researcher at Penetest Partners, a company that conducts ethical hacking of smart devices, called the new law “a step in the right direction.”
“I like that it has teeth,” he said.
In the past, he said, it was too easy for manufacturers to end support for older products as new models were released, so consumers should compare how many years of support the products they were purchasing were guaranteed. He said it would be convenient if it were possible.
Long support periods suggest that manufacturers generally take cybersecurity seriously, he said.
“Some device makers at the bottom of the market may pay lip service and do the bare minimum to ensure the safety of their products,” he said.
Rocio Concha, director of policy and advocacy at consumer group Which?, said the new law would give consumers “important protections”.
But he added that the Product Safety and Standards Agency should be prepared to “take strong enforcement action if manufacturers ignore the law”.
