"Chaves said the store owners told him the devices had remote access via Symantec’s pcAnywhere enabled, access that was granted to anyone knew the same set of default credentials."
Maybe its because The Cuckoo's Egg is what got me into this field, but I cringe everytime I hear this. Its 25 years later and we are still getting breaches based upon using default credentials.
This isn't even a hard problem to solve, you have three options: 1. Do not have a default password and prompt the user for one during setup. 2. Do not have the same default on every device, create it automagically from a serial number or something. 3. Have the system be unusable for the intended purpose until the default password is changed.