The UK Government is proposing new rules to ensure that IoT devices meet specific safety & security standards
Key rules include unique device passwords, a central point of contact to report vulnerabilities & a minimum period over which devices will receive security updates
So far there is no target date for the legislation, just a plan to get it done “as soon as possible”
Analysis and Comments
None of these rules look particularly demanding, which is an indication of how poor the current system is.
Analysts see the absence of standards around IoT security as being one of the biggest mid term barriers to a wider adaption in Smart City type applications
While analysts don’t expect consumers to become concerned enough to stop buying smart home devices such as smart door bells (despite the risks), they do believe governments & corporates will be more aware.
The fundamental problem is that the IoT largely lacks any established protocols around security (such as SAML, OAuth & OIDC).
While the UK regulation is a good first move, until the issue of security protocols is resolved its hard to see wider roll out of important technologies such as smart grids for households