Dahua's IoT devices, largely responsible for Krebs DDoS attack, have default passwords hardcoded in firmware; EU is working on IoT device security regulations
The European Commission is drafting new cybersecurity requirements to beef up security around so-called Internet of Things (IoT) …
Context & Ripple Effects
Dahua's hardcoded default passwords turned its IoT device fleet into the botnet behind the Krebs DDoS attack, and the European Commission's draft cybersecurity requirements are the first regulatory response to that failure mode. The pattern was already familiar to US enforcers: months later the FTC sued D-Link over routers and IP cameras that used hard-coded logins and exposed a private sign-in key.
What followed shows regulators converging on the same fix from different directions — a [[a:921053|Senate bill requiring government-purchased IoT devices to be patchable and free of hard-coded passwords]], the UK's later demand that vendors ship unique per-device passwords and disclose update lifetimes (unique-password rules), and ultimately the EU's own Cyber Resilience Act with fines attached.
First-order effects
- Dahua faces immediate pressure to strip hardcoded credentials from firmware and push updates to an installed base of devices that were never designed to be patched.
- The European Commission's draft requirements give EU market access a security condition, making compliance a design-stage cost for every IoT vendor selling into Europe.
Second-order effects
- Rivals and adjacent vendors like D-Link get pulled into enforcement by template: once regulators treat hardcoded logins as actionable negligence, every camera and router maker with similar firmware inherits the legal exposure.
- Procurement becomes the second lever — government buyers following the Senate bill's patchability standard can lock non-compliant vendors out of public contracts regardless of what Brussels or the FTC does.
Third-order effects
- If the EU, UK, and US requirements converge, default-password IoT effectively becomes unsellable in major markets, forcing device makers to build update infrastructure and credential provisioning into products rather than bolting security on after deployment.
- Liability shifts up the stack: as fines and suits attach to shipped firmware, retailers and integrators may start demanding security attestations from suppliers, restructuring who bears breach costs across the IoT supply chain.
The trend: IoT security is moving from voluntary best practice to enforceable law, with the Krebs DDoS attack as the incident that gave regulators in the EU, UK, and US their common playbook against hardcoded credentials.