TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Tougher rules for sellers of internet-enabled devices in the UK

43 点作者 timmb大约 1 年前

6 条评论

askvictor大约 1 年前
We had to recently look at this as we sell our product in the UK. The rules are really quite pissweak. From the article:<p>* that password procedures are more secure, including ensuring any set by the manufacturer are not left blank or using easy-to-guess choices like &quot;12345&quot; or &quot;admin&quot;<p>Reasonable. But that&#x27;s a _really_ low bar.<p>* that there is clarity around how to report &quot;bugs&quot; or security problems that arise<p>i.e. an email address published on the vendor website. No actual requirement to take action.<p>* that manufacturers and retailers inform customers how long they will receive support, including software updates, for the device they are buying<p>which means nothing if the manufacturer goes bankrupt.
评论 #40209077 未加载
评论 #40208296 未加载
评论 #40208237 未加载
评论 #40208557 未加载
评论 #40209587 未加载
评论 #40208747 未加载
评论 #40208365 未加载
评论 #40209604 未加载
Beretta_Vexee大约 1 年前
It&#x27;s a greatly diluted version of article relative to IoT from the European Cybersecurity Act (Regulation (E.U.) 2019&#x2F;881 of April 17 2019), 4 years after everyone.<p><a href="https:&#x2F;&#x2F;eur-lex.europa.eu&#x2F;legal-content&#x2F;EN&#x2F;TXT&#x2F;PDF&#x2F;?uri=CELEX:32019R0881&amp;amp;from=EN" rel="nofollow">https:&#x2F;&#x2F;eur-lex.europa.eu&#x2F;legal-content&#x2F;EN&#x2F;TXT&#x2F;PDF&#x2F;?uri=CELE...</a><p>Nothing new or interesting. If the products were already on the market in the European Union, they had already been subject to stricter requirements for 4 years.<p>The only change is that seller now have to display this information in the UK, whereas before they were not obliged to do so.
petepete大约 1 年前
While this move is clearly sensible the number of people importing absolute junk from Temu&#x2F;AliExpress&#x2F;Shein means millions of homes will be exploitable regardless.
评论 #40209178 未加载
评论 #40208493 未加载
评论 #40208617 未加载
评论 #40208459 未加载
评论 #40208244 未加载
surfingdino大约 1 年前
&gt; that manufacturers and retailers inform customers how long they will receive support, including software updates, for the device they are buying<p>This is important. I noticed Epson publishing information on the length of support for their printers already.
Fizzadar大约 1 年前
Heh, saw the UK in the headline and expected another leap towards our 1984 inspired future. Nice to see a change that actually benefits us that live here! Small step in the right direction.
评论 #40209793 未加载
leoedin大约 1 年前
The law itself says very little about what products do - it works similarly to other laws around machines and devices, where the heavy lifting is relegated to industry accepted standards. This is how CE marking (and the somewhat stalled UKCA mark) works - the law says you have to show that your device complies with industry standards, you produce a bunch of documentation showing this, you can give it a CE mark. It&#x27;s all self-certified - there&#x27;s no central body which will check.<p>It was surprisingly hard to work out the actual standards you need to comply with. It seems it&#x27;s mostly ETSI EN 303 645, which is an IoT security standard for consumer devices. This is actually a fairly pragmatic checklist of things your device should do. It&#x27;s a good thing this is now mandated by law. You can see the standard here: <a href="https:&#x2F;&#x2F;www.etsi.org&#x2F;deliver&#x2F;etsi_en&#x2F;303600_303699&#x2F;303645&#x2F;02.01.01_60&#x2F;en_303645v020101p.pdf" rel="nofollow">https:&#x2F;&#x2F;www.etsi.org&#x2F;deliver&#x2F;etsi_en&#x2F;303600_303699&#x2F;303645&#x2F;02...</a><p>There&#x27;s an ARM &quot;Platform Security&quot; framework which cross-checks against that standard - so if you can tick all their boxes you&#x27;re compliant with the law. <a href="https:&#x2F;&#x2F;www.arm.com&#x2F;architecture&#x2F;psa-certified" rel="nofollow">https:&#x2F;&#x2F;www.arm.com&#x2F;architecture&#x2F;psa-certified</a><p>It&#x27;s nice that this standard is openly available - so many of the standards you must comply with to legally sell a product in the EU are hidden behind expensive paywalls. It&#x27;s absurd that complying with EU and UK law requires paying a 3rd party sometimes hundreds of Euros.
评论 #40209073 未加载