<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: California passes law that bans default passwords in connected devices in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/California-passes-law-that-bans-default-passwords-in-connected/m-p/15310#M504</link>
    <description>&lt;P&gt;The next step should be to ban all most popular passwords a'la 123456, password123 or defining mandatory regex for passwords should be even easier.&lt;/P&gt;</description>
    <pubDate>Sat, 06 Oct 2018 17:51:59 GMT</pubDate>
    <dc:creator>ro83</dc:creator>
    <dc:date>2018-10-06T17:51:59Z</dc:date>
    <item>
      <title>California passes law that bans default passwords in connected devices</title>
      <link>https://community.isc2.org/t5/Tech-Talk/California-passes-law-that-bans-default-passwords-in-connected/m-p/15297#M503</link>
      <description>&lt;P&gt;No more "admin/admin" or "password/password". Enforcement and penalties are not mentioned.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://techcrunch.com/2018/10/05/california-passes-law-that-bans-default-passwords-in-connected-devices/?yptr=yahoo" target="_self"&gt;https://techcrunch.com/2018/10/05/california-passes-law-that-bans-default-passwords-in-connected-devices/?yptr=yahoo&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Oct 2018 21:40:54 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/California-passes-law-that-bans-default-passwords-in-connected/m-p/15297#M503</guid>
      <dc:creator>kpinkham</dc:creator>
      <dc:date>2018-10-05T21:40:54Z</dc:date>
    </item>
    <item>
      <title>Re: California passes law that bans default passwords in connected devices</title>
      <link>https://community.isc2.org/t5/Tech-Talk/California-passes-law-that-bans-default-passwords-in-connected/m-p/15310#M504</link>
      <description>&lt;P&gt;The next step should be to ban all most popular passwords a'la 123456, password123 or defining mandatory regex for passwords should be even easier.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Oct 2018 17:51:59 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/California-passes-law-that-bans-default-passwords-in-connected/m-p/15310#M504</guid>
      <dc:creator>ro83</dc:creator>
      <dc:date>2018-10-06T17:51:59Z</dc:date>
    </item>
    <item>
      <title>Re: California passes law that bans default passwords in connected devices</title>
      <link>https://community.isc2.org/t5/Tech-Talk/California-passes-law-that-bans-default-passwords-in-connected/m-p/15311#M505</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/467994801"&gt;@kpinkham&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;No more "admin/admin" or "password/password". Enforcement and penalties are not mentioned.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://techcrunch.com/2018/10/05/california-passes-law-that-bans-default-passwords-in-connected-devices/?yptr=yahoo" target="_self"&gt;https://techcrunch.com/2018/10/05/california-passes-law-that-bans-default-passwords-in-connected-devices/?yptr=yahoo&lt;/A&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;You can read the bill itself here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=201720180SB327" target="_blank"&gt;https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=201720180SB327&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the bill:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"(d)&amp;nbsp;This title shall not apply to any connected device the functionality of which is subject to security requirements under federal law, regulations, or guidance promulgated by a federal agency pursuant to its regulatory enforcement authority."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;My interpretation:&lt;/STRONG&gt; This law does not apply to any government systems or critical infrastructure systems that have legal or regulatory security mandates, such as FISMA or RMF or CSF.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"(e)&amp;nbsp;This title shall not be construed to provide a basis for a private right of action. The Attorney General, a city attorney, a county counsel, or a district attorney shall have the exclusive authority to enforce this title."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;My interpretation&lt;/STRONG&gt;: (a) it is up to state or local prosecutors to enforce the law. It is not clear that they would do so by filing criminal charges or by civil suit, but I suspect the latter.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(b) no private or personal civil lawsuits can use this law as the basis for the suit.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Oct 2018 18:07:29 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/California-passes-law-that-bans-default-passwords-in-connected/m-p/15311#M505</guid>
      <dc:creator>CraginS</dc:creator>
      <dc:date>2018-10-06T18:07:29Z</dc:date>
    </item>
  </channel>
</rss>

