Hacker News new | ask | show | jobs
by tlarkworthy 1987 days ago
https://hdivsecurity.com/owasp-broken-authentication

"Do not ship or deploy with any default credentials, particularly for admin users."

Though I wish OWASP published this guideline too. (they do state this is a top 10 venerability, and the HDIV scanner looks for this to fix)