To all developers reading this: it is YOUR responsibility to do everything you can to prevent your users from shooting themselves in the foot like this.
To all developers reading this: it is YOUR responsibility to do everything you can to prevent your users from shooting themselves in the foot like this.
[0] https://confluence.atlassian.com/bitbucketserver/install-a-b...
(Most resources I'm finding are only describing the importance of remembering to change the default password, rather than designing a system without a default password to begin with.)
"Do not ship or deploy with any default credentials, particularly for admin users."
Though I wish OWASP published this guideline too. (they do state this is a top 10 venerability, and the HDIV scanner looks for this to fix)
There's also a danger that if you try to do this, then your product turns into a UX nightmare.
And yes, sometimes security and UX conflict, and users just need to deal with it.