I cannot believe I'm hearing this. Especially from 3CX Partners and 3CX Certified members.
Actually - its not even good or bad strategy. Its the ONLY strategy to forcefully convert people to start securing their PBX properly.
Who argues that weak passwords are OK has absolutely no idea of cyber security - let alone defense and penetration. Especially a system for a paying customer.
In fact you keep extensions hack-able. (And some have been doing this for 7 YEARS!!!).
Moreover they can be hacked by these script kiddies launching the most standard tools of tools.
And you argue that this is ok because my system is "closed"...???!!! The sympathy I have is not for you - but I am really worried for the clients you represent.
One day, you WILL get a nice little bill with some high toll numbers to nice little numbers in Somalia, etc that you would have to cough up.. We will see then how confident you all remain...
@crsc - Well 7 years? Of course we will override an admin that reasons like this. A admin that values security would come up with this change proactively HIMSELF.
No this is not a potential nightmare. You just re provision and go ahead. 2 seconds.
It seems you still don't know what a potential nightmare is in computing and cyber security. I think you better not know trust me.
@ron Wiertz - Let me see if I got it right - Did you use the word "Closed" - This is getting even more educational !!!
I'm very sorry to say that this argument is completely baseless. Do you know that whatever "closed" system you think you might have, 70% of the attacks come in from TRUSTED SOURCES? How do you know whether some disgruntled employee decides to hijack your extension or that of the CEO?
How do you effectively "Close" your system to some guy that's already in your network?
@coertvc - So we have to jeopardize the security of 3CX and it's image because you are using Avaya phones (unsupported) and does not know how to change the password to a more complex one. This is not a very good argument...
The rude part is that you call the product not enterprise ready. Why can't you change and secure your endpoints?
Actually its a dishonor to all enterprise systems when you try and classify a phone configured your way as Enterprise.
@bwalker - We have Alpha, beta, rc candidates - I mean what do you want to alpha test? This is not a space launch.
You want a version to test that you can have a more secure password? Come on now. Do you test facebook when it asks you for a more secure password? Amazon AWS (Just mentioning 2 services that have billions of users here). You complain to them as well?
@Orlin - What features are not ready yet that you really really really need?
And why are you a premium partner after all these years still talking like this? This is really bad.
Its like you are a Mercedes sales executive assigned to sell the 2017 model, IN YOUR INTEREST TO SELL IT and when a customer comes and wants to buy a Mercedes you tell him - No buy the one of 2015!!!! What a cardinal error!!!
Conclusion:
I actually think FOR THE SAFETY of clients, I think I should immediately delete this thread.
I mean given I know already I'm preaching to the deaf, (I'm sure I'm going to get some amazing, genius answers soon), I'm not even concerned with your safety on the internet. But now I must step up because I have a vital concern here...
You cannot be entrusted and responsible to install 3CX for other customers if you completely disregard security this way. If you reason like this in 2017, you just cannot.
And this is why we enforce this. To make sure that cyber security negligence like this is FORCEFULLY Stopped. Whether you like it or not. This will never change inside 3CX.
And if you talk publicly like this, you put yourselves and your clients in danger. Only God knows what else you have configured insecurely. Because if you reason like this for your pbx (one of the most important and secure services in your business) then you reason like this for other things too.