California bill that would require “reasonable security” for all new IoT devices, the first of its kind in US, heads to governor's desk to be signed into law
Catalin Cimpanu / ZDNet : Tweets: @erratarob and @karlbode Tweets: @erratarob : California recently passed a law attempting to improve IoT security. It's bad. It's based on a naive, superficial understanding of the problem that won't solve security, while needlessly raising costs. http://blog.erratasec.com/... Karl Bode / @karlbode : Might be a good first step toward fixing the internet of broken things, but I'm doubting Chinese manufacturers are going to care. I like the push (by Consumer Reports and others) to include IOT security and privacy failures in product reviews, though. http://twitter.com/...
Context & Ripple Effects
California's bill arrives after two earlier attempts to legislate IoT security stalled or narrowed: a 2017 Senate bill covering only government-purchased devices, and an Illinois audio-consent bill substantially defanged by Internet Association lobbying. The California measure goes further by targeting every new device sold in the state, not just public procurement.
The reaction split along familiar lines: Errata Security's Robert Graham argues the 'reasonable security' standard reflects a superficial understanding that raises costs without fixing security, while Karl Bode doubts offshore manufacturers will comply and points to Consumer Reports' push to fold IoT security failures into product reviews as the more durable lever.
First-order effects
- Any manufacturer shipping connected devices into California — including the Chinese vendors Bode flags — must now design to a 'reasonable security' floor such as avoiding default credentials, with the state as the effective compliance gatekeeper for the US market.
- Security researchers and reviewers gain a legal benchmark to test against, strengthening Consumer Reports' effort to make security failures a visible part of product ratings.
Second-order effects
- Other governments respond with more prescriptive versions of the same idea: the UK proposes mandatory disclosure of update lifetimes and unique per-device passwords, and Singapore moves toward a labelling scheme for routers and smart hubs.
- Vague 'reasonable security' language invites litigation and lobbying pressure similar to what gutted the Illinois bill, pushing industry to seek preemption or a single federal standard rather than fifty state variants.
Third-order effects
- If the pattern holds, IoT security shifts from voluntary best practice to a market-access requirement set by whoever legislates first — a trajectory the EU later formalizes with its Cyber Resilience Act's fine-backed regime, leaving global manufacturers building to the strictest jurisdiction by default.
The trend: Consumer IoT security is moving from optional vendor promises to legally mandated minimums, with early-mover jurisdictions like California setting the de facto baseline for global supply chains.