Despite the takedown of the original Mirai botnet in 2016, Mirai-based attacks continue to pose a significant threat. According to Cloudflare’s DDoS threat report for Q1 2024, variants of Mirai are still prevalent, constituting a notable portion of HTTP and L3/4 DDoS attacks
Starting April 29, 2024, manufacturers of smart devices in the U.K. are now required to adhere to new legislation banning the use of default passwords. The move comes as part of the Product Security and Telecommunications Infrastructure (PSTI) act, introduced by the National Cyber Security Centre (NCSC), aimed at enhancing consumer protection against cyber threats.
Under this law, manufacturers must refrain from supplying devices with easily guessable default passwords, provide a designated point of contact for reporting security issues, and specify the duration for which devices will receive essential security updates. Notably, while default passwords are prohibited, a unique default password is allowed.
The legislation applies to a wide range of internet-connected products, including smart speakers, TVs, streaming devices, security cameras, smartphones, tablets, game consoles, wearable fitness trackers, and various smart domestic appliances like light bulbs, plugs, and thermostats.
Failure to comply with the PSTI act may result in recalls and hefty penalties, with fines of up to £10 million ($12.5 million) or 4 per cent of global annual revenues, whichever is higher. This makes the U.K. the first country globally to enforce such regulations against default usernames and passwords in IoT devices.
Despite the takedown of the original Mirai botnet in 2016, Mirai-based attacks continue to pose a significant threat. According to Cloudflare’s DDoS threat report for Q1 2024, variants of Mirai are still prevalent, constituting a notable portion of HTTP and L3/4 DDoS attacks.
The enactment of the PSTI act follows a significant fine imposed by the U.S. Federal Communications Commission (FCC) on major telecom carriers, including AT&T, Sprint, T-Mobile, and Verizon. The carriers were penalized for unlawfully sharing customers’ real-time location data with aggregators, who then sold the information to third-party service providers without proper consent.
U.S. Senator Ron Wyden, who exposed the practice in 2018, criticized the unauthorised sharing of personal location data, emphasizing that consumers did not expect their phone companies to sell detailed records of their movements to third parties.

