Simple never giving access would mean people can not open their router interfaces, self hosted stuff on SBCs ... so you make no sense.
Is it really? ISPs in USA/Canada/France/etc give customers WiFi routers with random passwords for many years.
Don't tell anyone though since that's a pretty big security risk.
> That malware, which worked as a botnet for the Russian hacking group Fancy Bear, was removed in January 2024 under a secret court order as part of "Operation Dying Ember," according to the FBI's director. It affected routers running Ubiquiti's EdgeOS, but only those that had not changed their default administrative password
No. It will block by default. If the header is present, it will allow the request.
> just throw up a dialog that says "the current page wants to connect to things on your home network
In many (probably most) cases it is just a work site trying to connect to an internal service on your work VPN, and the warnings would get annoying very quickly.