Nest seems to want to have a conversation with you!
IoT should have a baseline that once power is applied the setup process cannot continue until the default password is changed, and preferably to 2FA/MFA.
This is like having your mother talk to you from the grave chiding you to clean your room.
However, if there are no regulatory mandates or governance pushed by Country Government, there is very little chance that a voluntary code of practice will be adhered too, without the obligatory penalty or back to the supply chain issue. The issue needs to go back to the manufacturer - either an organisation or client purchases the product in good faith - we need to go back to principles and demand that this sort of thing is resolved at the supply chain level. Or it will only get worst and worst, at the moment it appears we skate over the subject as though we are becoming immune and ineffective.
Regards
Caute_cautim
That's why I mentioned it here. No better forum to breathe life into a topic that needs serious attention.