A default password scales into a fleet vulnerability
One default credential on one device is a small problem. The same credential on ten thousand deployed devices is a systemic one.
That is what makes factory defaults different from an ordinary weak password: it is not a mistake somebody made, it is a property of the product. The UK now prohibits universal default passwords on consumer connected devices for exactly this reason.
More on IoT and embedded
- Physical access changes the embedded threat modelThe lid was the threat model
- Firmware updates are a long-term security promiseYou sold the box, you signed up for the years
- Secure boot protects the startup chainEach link checks the next
- Device identity should be uniqueAll answering to one name
- Cloud shutdown can strand smart devicesThe strings came from elsewhere
- Sensors can be fooled without hacking softwareNo code was touched
