Cyber Experts Urge End to Risky Default Passwords in IoT Devices

Universal default passwords in IoT devices create massive security vulnerabilities that allow hackers to compromise thousands of products at once. Manufacturers must abandon this dangerous practice and adopt safer alternatives like physical resets and multifactor authentication.

Universal default passwords in consumer Internet-of-Things devices create massive security vulnerabilities that hackers easily exploit. Because these passwords are identical across mass-produced products, a single compromised credential leaves every matching device completely open to attack. This shared weakness allows malicious actors to deploy one piece of malware to hijack thousands of devices simultaneously.

The infamous Mirai botnet perfectly illustrates this danger by using just 60 known default username and password combinations to take over more than 500,000 IoT devices. Hackers target these poorly secured products within minutes of their connection to the internet. Shifting the responsibility to consumers to change these weak passwords fails to solve the underlying problem, meaning manufacturers must stop using this flawed practice entirely.

While some manufacturers argue that default passwords are necessary for account recovery and remote diagnostics, these benefits do not outweigh the severe security risks. Companies currently have safer alternatives available to achieve these same goals without relying on universal credentials. By leveraging physical access for factory resets or implementing multifactor authentication, the tech industry can effectively eliminate this widespread threat.

Read More at the original source →