UK law will hit smart home device makers with fines for using default passwords
engadget.com
engadget.com
A lot more convoluted, but you could make a nice CompanyNameDeviceSetup app, which could handle the minutiae.
The only (partial) solution I can imagine is someone creating an open-source software for resetting the password to a non-standard setting, then evangelizing the standard. There are a few issues with this, and it would require adding some standard interface (USB or other) to every such device.
Yes, this is expected. The point is to prevent a population of devices being sold with admin/admin pre-programmed.
Having the manufacture make it a permanent part of the device using something like engraving makes it more robust and harder to subvert. Unfortunately as a side effect it increases cost per unit.
The sticker's not that bad, but it depends on the devices usage scenario.
- manufacturers must tell customers up front about the lifespan of security patches and updates - manufacturers must provide a public point of contact for vulnerability disclosure