Podcast
Root Causes 55: California's New IoT Security Law


Hosted by
Tim Callan
Chief Compliance Officer
Jason Soroko
Fellow
Original broadcast date
December 5, 2019
California Senate Bill 327 (SB-327) goes into effect January 1, 2020. This groundbreaking ordinance requires basic security measures for devices deployed in California. Join us to learn what SB-327 requires from device manufacturers, which threats it protects against, and how this ordinance is leading the way toward stronger IoT security practices.
Podcast Transcript
Lightly edited for flow and brevity.
Yeah, Tim. So, the idea of the Mirai Botnet was fundamentally the reason why it worked - - the root cause of why the bad guys were able to harvest so many millions of these devices really came down to these static credentials. Credentials that either were very easy to guess because perhaps they were published or they were known. Perhaps there might have even been a mechanism to change the administrator’s user name and password to authenticate to these devices. Problem is the users of these devices didn't change them. So keep in mind, all this legislation is calling for is a mechanism to change hard-coded static credentials. That is all that the legislation is calling for at this point. It's not even asking for encrypted communication tunnels, TLS mutual authentication. It's not calling for any of that. It really is just that mechanism to change a default username and password, for example.

