House Dems urge FTC to issue warnings on IoT cybersecurity
Full article690 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The FTC has previously warned consumers to change default passwords on connected devices — default passwords are exploited by the Mirai botnet that infected hundreds of thousands of IoT devices and used them in the Oct. 24 DDoS attack that knocked many major websites offline.
The FTC should issue new warnings to consumers and new advice to connected-device manufacturers in the wake of last month’s massive DDoS attack that leveraged the Internet of Things, two leading Democrats on the House Energy and Commerce Committee urged last week.
“It is time for the FTC to strongly reinforce to both consumers and device manufacturers the need to adopt strong security measures,” Rep. Frank Pallone, D-N.J., and Rep. Jan Schakowsky, D-Ill., wrote in a letter Thursday to FTC Chairwoman Ramirez. “First, the FTC should call on IoT device manufacturers to implement security measures, including patching vulnerabilities and requiring consumers to change the default passwords on devices during the setup process. Second, the FTC should alert consumers to the security risks posed by continuing to use default passwords on IoT devices.”
Pallone is the ranking member of the full Energy and Commerce Committee, and Schakowsky is the ranking member on its Commerce, Manufacturing, and Trade Subcommittee.
The FTC has previously warned consumers to change default passwords on connected devices — default passwords are exploited by the Mirai botnet that infected hundreds of thousands of IoT devices and used them in the Oct. 24 DDoS attack that knocked many major websites offline.
While calling this advice “commendable,” the two Democrats wrote that additional warnings are necessary, both to consumers and to industry.
“Unfortunately, consumers do not always have the option of securing their own devices,” the two write, because “Some device manufacturers have chosen to hard-wire in default passwords, leaving consumers helpless.”
The FTC “is the only federal agency with responsibility for consumer protection across broad areas of the economy,” they add.
Pallone and Schakowsky asked that the FTC “immediately use all the tools at its disposal to ensure that manufacturers of IoT devices implement strong security measures to best protect consumers from cyberattacks.”
More Scoops
House Republicans roll out national privacy bill
Experts say the federal legislation takes inspiration from states laws in Virginia and Kentucky, but a lack of bipartisan support could spell trouble.
Wyden calls on FTC to investigate Microsoft for ‘gross cybersecurity negligence’ in protecting critical infrastructure
FTC announces settlement with toy robot makers that tracked location of children
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/house-dems-urge-ftc-warn-iot-cybersecurity/