/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

California bill that would require “reasonable security” for all new IoT devices, the first of its kind in US, heads to governor's desk to be signed into law

Catalin Cimpanu / ZDNet : Tweets: @erratarob and @karlbode Tweets: @erratarob : California recently passed a law attempting to improve IoT security. It's bad. It's based on a naive, superficial understanding of the problem that won't solve security, while needlessly raising costs. http://blog.erratasec.com/... Karl Bode / @karlbode : Might be a good first step toward fixing the internet of broken things, but I'm doubting Chinese manufacturers are going to care. I like the push (by Consumer Reports and others) to include IOT security and privacy failures in product reviews, though. http://twitter.com/...

ZDNet Catalin Cimpanu

Context & Ripple Effects

California's bill arrives after two earlier attempts to legislate IoT security stalled or narrowed: a 2017 Senate bill covering only government-purchased devices, and an Illinois audio-consent bill substantially defanged by Internet Association lobbying. The California measure goes further by targeting every new device sold in the state, not just public procurement.

The reaction split along familiar lines: Errata Security's Robert Graham argues the 'reasonable security' standard reflects a superficial understanding that raises costs without fixing security, while Karl Bode doubts offshore manufacturers will comply and points to Consumer Reports' push to fold IoT security failures into product reviews as the more durable lever.

First-order effects

  • Any manufacturer shipping connected devices into California — including the Chinese vendors Bode flags — must now design to a 'reasonable security' floor such as avoiding default credentials, with the state as the effective compliance gatekeeper for the US market.
  • Security researchers and reviewers gain a legal benchmark to test against, strengthening Consumer Reports' effort to make security failures a visible part of product ratings.

Second-order effects

  • Other governments respond with more prescriptive versions of the same idea: the UK proposes mandatory disclosure of update lifetimes and unique per-device passwords, and Singapore moves toward a labelling scheme for routers and smart hubs.
  • Vague 'reasonable security' language invites litigation and lobbying pressure similar to what gutted the Illinois bill, pushing industry to seek preemption or a single federal standard rather than fifty state variants.

Third-order effects

  • If the pattern holds, IoT security shifts from voluntary best practice to a market-access requirement set by whoever legislates first — a trajectory the EU later formalizes with its Cyber Resilience Act's fine-backed regime, leaving global manufacturers building to the strictest jurisdiction by default.

The trend: Consumer IoT security is moving from optional vendor promises to legally mandated minimums, with early-mover jurisdictions like California setting the de facto baseline for global supply chains.