Off-Prem

Edge + IoT

European Commission airs out new IoT device security draft law – interested parties have a week to weigh in

Mirroring UK, US efforts to crack down on cheap 'n' cheerful internet gadgets


Infosec pros and other technically minded folk have just under a week left to comment on EU plans to introduce new regulations obligating consumer IoT device makers to address online security issues, data protection, privacy and fraud prevention.

Draft regulations applying to "internet-connected radio equipment and wearable radio equipment" are open for public comment until 27 August – and the resulting laws will apply across the bloc from the end of this year, according to the EU Commission.

Billed as assisting Internet of Things device security, the new regs will apply to other internet-connected gadgets in current use today, explicitly including "certain laptops" as well as "baby monitors, smart appliances, smart cameras and a number of other radio equipment", "dongles, alarm systems, home automation systems" and more.

"The key objective of this initiative is to contribute to strengthen the 'ecosystem of trust' which stems from the synergies of all related pieces of EU law concerning protection of networks, privacy and against fraud," said the explanatory note on the draft EU regulation, a summary of which is downloadable via the link above.

"This initiative should then allow on the EU market only the radio equipment that is sufficiently secure."

The Netherlands' FME association has already raised public concerns about the scope of the EU's plans, specifically raising the "feasibility of post market responsibility for cybersecurity".

The trade association said: "If there is a low risk exploitable vulnerability; at what level can the manufacturer not release or delay a patch, and what documentation is required to demonstrate that this risk assessment was conducted with this outcome of a very low risk vulnerability?"

While there are certainly holes that can be picked in the draft regs, cheap and cheerful internet-connected devices pose a real risk to the wider internet because of the ease with which they can be hijacked by criminals.

The proposed EU regs are similar to those being floated in the UK to tighten up IoT security; rules which were also suddenly widened to cover mobile phones and tablets. Previously the legislation had been sold as a way of securing otherwise painfully insecure IoT devices; GCHQ offshoot the National Cyber Security Centre, a major sponsor of the Secured by Design initiative, may have had the Mirai botnet in mind.

Identity management firm Sectigo's CTO Jason Soroko told The Register, in an interview about botnets and router security, that poor security in these devices stems from industry design choices intended to ease deployment, use and configuration: "If you and I right now, were to investigate the top five latest [routers], would we find a huge difference in terms of how they're built? Would we find open Telnet ports? I bet you we would. Would we find vulnerabilities in terms of weak credential form factors for PHP web interface code?"

Soroko thought the answer was obvious. Certain router makers have learned the hard way that end-of-life equipment that contain insecurities can have a reputational as well as security impact. That said, it's perhaps unreasonable to expect kit makers to keep providing software patches for years after they've stopped shipping a device. Consumers cannot rely on news outlets shaming makers of internet-connected goods into providing better security; new laws are the inevitable next stage, and there's a growing push for them on both sides of the Atlantic.

Device makers being banned from selling in the EU over security and data protection issues is not new. In 2017, the German telecoms regulator banned the sale of children's smartwatches that allowed users to secretly listen in on nearby conversations and later that year, the French data protection agency issued a formal notice to a biz peddling allegedly insecure Bluetooth-enabled toys – Genesis Toys' My Friend Cayla doll and the i-Que robot, because the doll could be misused to eavesdrop on kids. The manufacturers are also obliged to comply with the GDPR. However, the new draft law is evidence that certain loopholes might soon begin to close. ®

Send us news
13 Comments

Look for the label: White House rolls out 'Cyber Trust Mark' for smart devices

Beware the IoT that doesn’t get a security tag

GoDaddy slapped with wet lettuce for years of lax security and 'several major breaches'

Watchdog alleged it had no SIEM or MFA, orders rapid adoption of basic infosec tools

Biden signs sweeping cybersecurity order, just in time for Trump to gut it

Ransomware, AI, secure software, digital IDs – there's something for everyone in the presidential directive

Microsoft eggheads say AI can never be made secure – after testing Redmond's own products

If you want a picture of the future, imagine your infosec team stamping on software forever

CISA: Wow, that election had a lot of foreign trolling. Trump's Homeland Sec pick: And that's none of your concern

Cyber agency too 'far off mission,' says incoming boss Kristi Noem

After China's Salt Typhoon, the reconstruction starts now

If 40 years of faulty building gets blown down, don’t rebuild with the rubble

Miscreants 'mass exploited' Fortinet firewalls, 'highly probable' zero-day used

Ransomware 'not off the table,' Arctic Wolf threat hunter tells El Reg

Ransomware crew abuses AWS native encryption, sets data-destruct timer for 7 days

'Codefinger' crims on the hunt for compromised keys

Mitel 0-day, 5-year-old Oracle RCE bug under active exploit

3 CVEs added to CISA's catalog

Database tables of student, teacher info stolen from PowerSchool in cyberattack

Class act: Cloud biz only serves 60M-plus folks globally, no biggie

FCC to telcos: By law you must secure your networks from foreign spies. Get on it

Plus: Uncle Sam is cross with this one Chinese biz over Salt Typhoon mega-snooping

Just as your LLM once again goes off the rails, Cisco, Nvidia are at the door smiling

Some of you have apparently already botched chatbots or allowed ‘shadow AI’ to creep in