be sufficiently randomised using a random function. 3. Passwords must not be relatable in an obvious manner to public information such as MAC address or Wi-Fi SSID. The developer shall also provide 5 instances of randomised passwords that are generated using the aforementioned password randomisation mechanism to CCC. 5.1-3: Authentication mechanisms used to authenticate users against a device shall use best practice cryptography, appropriate to the properties of the technology, risk and usage. M M M M Please note that there are many mechanisms used for performing authentication, and passwords are not the only mechanism for authenticating a user to a device. If other authentication mechanisms are used, please provide details. Supporting evidence shall list all authentication mechanisms (e.g. passwords, tokens, smart cards, digital signatures, biometrics, etc.) available for the various device login-interfaces (e.g. device configuration portal, companion mobile application, etc.), and describe how each of the mechanisms are adequately secured to address the risk CLS Publication #2 | Page 23 of 49

Select target paragraph3