This is SOP for IOT devices. I am beginning to think we need to regulate this stuff, because it is ubiquitous. The device manufacturers do not have a culture of security.
There are much better ways of device enrollment; at a minimum they could require device activation that doesn't blindly use a token with no further checks.
There are much better ways of device enrollment; at a minimum they could require device activation that doesn't blindly use a token with no further checks.