This will end up just being really annoying and accomplish nothing, like most corporate password policies. It would be nice to see a focus on actually solving the problem, instead of the usual liability transfer. Best case scenario, the password is written on a sticker on the device. This is the norm where I live. I would love to see incentives for actual user friendly security enhancements.
The sticker (while cost effective) is still problematic.
Having the manufacture make it a permanent part of the device using something like engraving makes it more robust and harder to subvert. Unfortunately as a side effect it increases cost per unit.
The sticker's not that bad, but it depends on the devices usage scenario.
Comments
This will end up just being really annoying and accomplish nothing, like most corporate password policies. It would be nice to see a focus on actually solving the problem, instead of the usual liability transfer. Best case scenario, the password is written on a sticker on the device. This is the norm where I live. I would love to see incentives for actual user friendly security enhancements.
Yes, this is expected. The point is to prevent a population of devices being sold with admin/admin pre-programmed.
Credential being stored on a sticker on the device does help against the device being remotely enrolled in a ddos/spam botnet.
The sticker (while cost effective) is still problematic.
Having the manufacture make it a permanent part of the device using something like engraving makes it more robust and harder to subvert. Unfortunately as a side effect it increases cost per unit.
The sticker's not that bad, but it depends on the devices usage scenario.