Consumer device cyber standards have arrived to teach smart gadgets the ancient human art of behaving sensibly. The lesson starts with a radical rule: a connected kettle should not defend itself with the password “password”.
Consumer device cyber standards enter the smart home
The Department for Science, Innovation and Technology announced on 23 October that the UK and Singapore would work together on consumer device cyber security standards.
The UK regime includes minimum protections for connected consumer devices. It also bans common default passwords. Manufacturers must provide information about how long software updates will last.
At the launch, fictional standards coordinator Alma Footnote welcomed the plan. “We are asking devices to show basic responsibility,” she said. “These objects have spent years connecting themselves to the internet without checking whether they had anything useful to say.”
The arrangement aims to help standards work across borders. Devices that meet Singapore’s standards would receive protection under the UK regime.
International cooperation has achieved what household technology has not. Two separate systems now agree that a doorbell should not use “admin” as its entire security policy.
Updates become part of the sales pitch
Manufacturers must also provide information about software update periods. Buyers can then discover whether a product will remain supported. They may even learn this before they finish finding the reset button.
Fictional director Simon Semicolon, of the Office for Appliances That Know Too Much, called the change “a landmark in moving vital information from page twelve of the manual to somewhere a human might accidentally see it”.
Consumer device cyber standards now ask connected products to accept some responsibility for their own behaviour. That is awkward for appliances marketed as intelligent. They still demand an account, an email confirmation, permission to inspect the home and a password reset whenever the toaster develops an opinion.
The smart gadget industry may need time to adjust. Some devices are still learning that a software update is not a personal insult. They also need to learn that connecting to everything in the house is not the same as having a personality.
The announcement presents a serious effort to make connected products safer across markets. The satire sits in the ambition. Gadgets have been sold as brilliant objects while failing to recognise a security risk unless it arrives with a flashing light.
By the time the smart home is secure, its devices may even stop announcing their passwords through the letterbox. At which point the kettle will be the only member of the household refusing to discuss its internal affairs.