There's a completely different mindset at work. As web developers, most of the HN population is acutely aware of the need for proper authentication of users and securing communications. The average embedded systems engineer is not. It likely will never even occur to him that someone other than the guy at the other end will want to control his system/hack into it.
This is changing (I'm seeing specifications for new systems that at least have placeholders for "Security"), but it will be slow and painful. Remember that at the low end, there are still engineers who can't understand why everyone isn't writing their programs in Assembly.
This is changing (I'm seeing specifications for new systems that at least have placeholders for "Security"), but it will be slow and painful. Remember that at the low end, there are still engineers who can't understand why everyone isn't writing their programs in Assembly.