Can’t believe Tesla would ship something with anything resembling a default password. At first glance, I assumed this would be a clear violation of the requirements of CA SB-327 (goes into effect Jan 1). Reread the bill, and it actually says: “The preprogrammed password is unique to each device manufactured.” If the default is based on the serial number, I guess it’s “unique” under the letter, but certainly not the s…
I disagree. The spirit of the law is to ensure that logins cannot be automated. Unless the serial number can be read over the internet without authentication, using it is completely within the spirit of the law.
As I said in my post below, I just checked mine and the full serial number is included in the device hostname. Since tons of regular PW installs are going to average joe residential sites which will heavily be using crappy outdated ISP provided routers with default passwords and entirely flat unmonitored LANs, possibly with infected machines to boot, it's fair to say that yes in fact the serial number will be able to be read over the internet without any authentication. Anyone who can see hostnames of devices on the LAN can get the whole serial.
Although I also doubt any such network will have any real rate limiting or notice any hammering either, and the serials look utterly trivial to brute force. So I'm not sure the fact that they're all broadcast for everyone even ultimately makes much difference.