So looking at:

https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=201720180SB327

**********************************************************************************************************************************************
SECTION 1. Title 1.81.26 (commencing with Section 1798.91.04) is added
to Part 4 of Division 3 of the Civil Code, to read:

TITLE 1.81.26. Security of Connected Devices

1798.91.04. (a) A manufacturer of a connected device shall equip the
device with a reasonable security feature or features that are all of
the following:
(1) Appropriate to the nature and function of the device.
(2) Appropriate to the information it may collect, contain, or transmit.
(3) Designed to protect the device and any information contained
therein from unauthorized access, destruction, use, modification, or
disclosure.
(b) Subject to all of the requirements of subdivision (a), if a
connected device is equipped with a means for authentication outside a
local area network, it shall be deemed a reasonable security feature
under subdivision (a) if either of the following requirements are met:
(1) The preprogrammed password is unique to each device manufactured.
(2) The device contains a security feature that requires a user to
generate a new means of authentication before access is granted to the
device for the first time.
**********************************************************************************************************************************************


So to meet (1), should we just use the "serial number" on the side of
the board, or mac address, etc...?

Or to meet (2), require use to change default password, the problem,
#2 States: "before access is granted"...  My initial fix is "after
access is granted"...

Or Option 3: ship the boards blank... ;)

and what about "root:root"... do we nuke "root" by default and just
let the user init it...

Regards,

-- 
Robert Nelson
https://rcn-ee.com/

-- 
For more options, visit http://beagleboard.org/discuss
--- 
You received this message because you are subscribed to the Google Groups 
"BeagleBoard" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/beagleboard/CAOCHtYg6d6NXySQkB76kZBEdBA%3DuOny5sjm%3DnN1RsB%3D7j34oug%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to