Insecure by default is flawed by default.
Unless a product requires certification to use it can’t rely on expert knowledge to provide safety.
Unless a product requires certification to use it can’t rely on expert knowledge to provide safety.
Of course, from a security standpoint, people will still make mistakes like this, but the onus is NOT on the tool developers. They make it configurable for a reason.
Is it really that difficult to require someone to set a secure password before a product is usable?