I’m genuinely curious how this happens. I remember my first job in the industry, just out of university. I knew nothing about security, but still wouldn’t have done that. My first gig was in a credit union software company, and the security standards were nonexistent, yet we still had more reasonable passwords than this (which sounds like an installation default).
Security is a cost and nuisance. It's the first thing to be cut. To keep high security at all times you need: 1) Process aka bureaucracy. Mandatory checklists. Checklists are returned and inspected by others. Anything missing or uncertain is checked again and fixed. 2) People who are responsible for security are independent from other concerns. They can have adversarial relationship with people responsible for gettin…
Dealing with standard practices, most especially violations of your #2, have contributed in large part to my getting off this ride.