Wednesday, October 7, 2026

Default Password Ban: Why Labels Fail

Every router, camera and smart plug sold in the United States should be legally required to carry a password unique to that unit, or make you set your own, before it touches your Wi-Fi. Britain has enforced exactly that default password ban since 29 April 2024. America chose a sticker. The standard objection says a voluntary label lets shoppers reward careful makers without Washington writing firmware rules. It sounds reasonable, until you see what the sticker has done since.

Infographic arguing for a default password ban, with a router and an open padlock

Key Takeaways: a ban works because it covers every box on the shelf; a voluntary label covers only the makers who choose to apply.

  • British buyers get unique or user-set passwords on smart devices by law, no label needed.
  • The US label is optional, so a maker that skips it loses nothing but a sticker.
  • California and Oregon prove makers can comply, so a federal rule mostly extends firmware they already ship.
  • Until Washington acts, check for a unique or set-your-own password before you buy.

Why a default password ban beats a label

A ban beats a label because it protects the buyer who never reads packaging, never registers the device and never changes a setting, while a label protects only the shopper who already knows to look for it.

The British version, set out on GOV.UK's product security regime page, is blunt: passwords must be unique per product or set by the user. Makers must also publish a route for reporting security bugs and say how long they will ship security updates. A British buyer gets that protection without knowing the law exists, which is the whole point of a rule.

America took the other road. The FCC approved the US Cyber Trust Mark on 14 March 2024 as a voluntary label, CyberScoop reported, so a US shopper gets password protection only when a maker opts in. Its lead administrator, UL Solutions, then withdrew on 19 December 2025 amid an FCC probe into its China ties, says Cybersecurity Dive. The FCC named the ioXt Alliance in its place on 13 April 2026, Broadband Breakfast reported, and won't pay for the job. By my count, the label shoppers were told to trust sat with nobody in charge for nearly four months.

Washington has been here before: its memory safety roadmap deadline for critical-infrastructure software carried no penalty and passed quietly. Europe binds vendors instead, as the Cyber Resilience Act's 24-hour vulnerability warning shows. Four figures from GOV.UK, the PSTI Act 2022 and Broadband Breakfast show the gap.

UK Rule in Force So Far

29 months

Every UK sale since April 2024

FCC Money for the US Label's Administrator

$0

Runs on industry goodwill

Legal Duties on Each UK Device

3

Covered without reading anything

Top UK Fine as Share of Revenue

4%

Scales up for global brands

A fine pegged to worldwide turnover is too big for a global router brand to treat as a cost of selling in Britain, so the cheap answer is one firmware build for every market. You just can't tell from a US box which makers did it.

"

Britain needed no sticker to make every router safer. Washington's sticker can't even pay the people meant to run it.

Does the UK ban default passwords on smart devices?

Yes, the UK has banned universal default passwords on consumer connected devices since 29 April 2024, requiring each product to ship with a unique password or make the buyer set one, under the Product Security and Telecommunications Infrastructure regime.

The table sets that law against the US label, read as a buyer standing in a store.

Dimension UK law vs US label What it means for you
💰 Cost of skipping UK Fines up to £10 million
US No penalty at all
❌ US makers risk nothing by opting out
⚖️ Who must comply UK Every maker selling there
US Only makers that apply
⚠️ In a US store, you vet each box
🔒 Password rule UK Unique or user-set, all models
US Same idea, labelled models
✅ Labelled gear meets the British bar
🛠 Who runs it UK A standing regulator, OPSS
US No lead for 115 days
❌ Oversight can lapse with no warning
🌍 Coverage UK The whole country
US State law in 2 of 50
⚠️ Your ZIP code sets your protection
🏁 Best suited for UK Any buyer, no homework
US Buyers who read every box
🏁 Law wins whenever a shopper is rushed

Read down the right-hand column: the label helps only buyers who already do the work. The first-row fine comes from the PSTI Act 2022; the 115-day gap is my arithmetic from the reported dates above.

California. and Oregon. 2020 State law, in force. United Kingdom. 2024 National law, in force. European Union. Dec 2027 Law, applies soon. US federal level. None Voluntary label only.

Outside California and Oregon, no US law guarantees that the next router you buy ships with a unique password. Dates come from each jurisdiction's own text: California SB-327, the UK PSTI regime and EU Regulation 2024/2847.

Do routers have to come with unique passwords?

Only in some places: in Britain since April 2024, in California and Oregon since 2020, and across the EU from December 2027, while a router sold in the other 48 US states can still legally share one factory password.

California's SB-327, operative since 1 January 2020 (as of 2020), demands a password "unique to each device manufactured" or one the user creates. Oregon passed a near-copy. The EU's Cyber Resilience Act, on EUR-Lex, requires a secure by default configuration once its main obligations apply on 11 December 2027. So the "too costly" objection collapses: the engineering exists, and the biggest US state has demanded it for years.

The second objection calls default passwords a niche consumer worry. CISA disagrees. In December 2023 (as of 2023) its Secure by Design alert urged makers to drop default passwords after attackers reached Unitronics controllers at US water facilities; CyberScoop reported their factory password was 1111, so one shared login opened every identical unit. The federal security agency called it a manufacturer failure in writing, then only asked nicely. As with post-quantum migration deadlines, guidance without teeth moves at the pace of the slowest vendor.

One grey area remains, and this is opinion: should a federal rule reach devices already in homes? I'd cover new sales only, because retroactive rules invite lawsuits that stall everything. Watch-outs meanwhile:

  • A Cyber Trust Mark helps, but its absence proves nothing.
  • An app-based setup can leave the local web login on its factory value.
  • Marketplace imports may follow no national rule.

Check these before the device goes on your network

  • Setup forces you to create your own admin password, or the label shows one unique to that unit.
  • The maker's site names a security-update end date for your model.
  • The maker publishes a way to report security bugs.
  • The login printed in the manual stops working after setup.

So here's the decision. If you're in the US, treat the label as a bonus and the password check above as the real test, and this week log in to your own router and replace any password printed in its manual. Then tell your representative that Britain already proved the rule costs makers almost nothing.

No comments

Post a Comment