Author Topic: P132/P332 - FCC Cybersecurity Rules  (Read 1382 times)

bobcvols

  • Newbie
  • *
  • Posts: 8
P132/P332 - FCC Cybersecurity Rules
« on: September 25, 2026, 03:44:54 pm »
Good morning, Jan -

We have 3 P332's that we use on three facilities - extremely dependent!

We are staring down new U.S. FCC cybersecurity rules which require enhanced security measures for our EAS system and devices that are connected to it through our program chain.  RDS units have been mentioned in some of the discussion that I have seen, although that may refer to RDS that is generated by transmitters.  Here is a set of FCC FAQ's that it released earlier this week:
https://www.fcc.gov/faqs-EAS-Cybersecurity-Requirements

Do the Pira boxes qualify, in your estimation?  If so, with our exposure to the Internet, I wanted to change our password on these units to a 15-character, randomly-generated password.  But, the Pira interface only allows me to insert 10 characters. What would you suggest?

Thanks!

Jan

  • Hero Member
  • *****
  • Posts: 1342
Re: FCC Cybersecurity Rules
« Reply #1 on: September 25, 2026, 04:12:25 pm »
We are preparing an update to the internal website that will allow you to set a longer password than is currently possible. While this will not affect security in any way, it will ensure formal compliance with an FCC requirement.

If you do not want to wait, you can set a 15-character password right now. Use the Magic RDS 4 program's GUI to do so.

Bob Crittenden

  • Guest
Re: FCC Cybersecurity Rules
« Reply #2 on: September 25, 2026, 04:54:20 pm »
Thanks for your prompt response!  I don't use Magic RDS, but I probably need to start using it.  Is there a link to a tutorial that is available?
Bob

kdincville

  • Newbie
  • *
  • Posts: 2
Re: FCC Cybersecurity Rules
« Reply #3 on: October 02, 2026, 10:25:08 pm »
I am attempting to log in to my 3) P332 encoders after installing 15 character passwords as previously demonstrated. So far, I appear to be locked out. I am wondering if the message in front of the password box is telling me to add characters in front of the password, or what its purpose is. I'd also like to know how to reset to a zero password condition.
 
WEB password (AT+iWpwd):

Thanks.
kd

Jan

  • Hero Member
  • *****
  • Posts: 1342
Re: FCC Cybersecurity Rules
« Reply #4 on: October 03, 2026, 12:05:19 am »
Yes, you are right. We discovered today that, due to timing issues, logging into the web interface of this old device from modern computers can indeed be hit-or-miss. It is possible to log in, but not always on the first attempt (you must press Reload before attempting to submit again). We have identified the cause in the internal website and are working on a solution. We will keep you updated over the coming days. In any case, by following the procedure described above, you have formally satisfied the FCC requirement.
As a temporary solution, use this URL to access password-protected internal website on modern browsers:
http://<device IP address>/?RESP=secure

Jan

  • Hero Member
  • *****
  • Posts: 1342
Re: P132/P332 - FCC Cybersecurity Rules
« Reply #5 on: October 03, 2026, 12:08:19 pm »
Version 2.2a of the embedded website:

https://pira.cz/rds/p132webu.zip
https://pira.cz/rds/p332webu.zip

Instructions included.

Release notes for the version 2.2a:
  • The password length restriction when setting it up via the website has been removed. It is now possible to enter a password of up to 15 characters.
  • Bug fix: If a password had been set, logging in via the standard URL sometimes failed on certain modern browsers.

If you are going to update the website, I also recommend updating the RDS firmware to prevent any potential incompatibility:
https://pira.cz/rds/p132fwup.zip (valid for entire RDS encoder's family)

kdincville

  • Newbie
  • *
  • Posts: 2
Re: P132/P332 - FCC Cybersecurity Rules
« Reply #6 on: October 04, 2026, 10:15:43 pm »
Jan- Thanks for all the information and the super quick response.
I was able to unlock two of the three units, get their address changed, and get them back in service. Unfortunately, the third one isn't cooperating. After entering the password, it looks like it's unlocked, but after a second or two it reverts to the login screen. It does this using all three iterations of the logon addresses I have: the plain, bare, IP address; the http://<device IP address>/?RESP=secure logon; and http://<encoder’s IP address>/ichip login from the new software package instructions.
At this point I'm thinking that the path of least resistance is to just reset it back to the factory settings and start over. Can you tell me how to do that? Thanks in advance... k

Jan

  • Hero Member
  • *****
  • Posts: 1342
Re: P132/P332 - FCC Cybersecurity Rules
« Reply #7 on: October 05, 2026, 03:06:32 am »
No, that's not how it works; this isn't an Android phone  :)
If the webpage did not upload correctly, simply upload it again. This process takes place solely between your browser and the ConnectOne network module, and this is one of its characteristics that we cannot influence.