Do I understand this correctly? Are you saying you removed that root password, such that it wasn't possible to log in with another (but different) root password?
Or are you saying that you merely changed it, to one the customer no longer knew, but was the same password across all of your install base, for every customer?
It was at that moment a simple change of the password. The benefit was that people outside of our company wouldn't have access (thus not sharing it further), and then as a future improvement we could have implemented some better key scheme. But while customers want to have root access it is not an option.
Theoretically we could implement a scheme with individual passwords or keys per device (as someone suggested in the comments above), but such thing is not being prioritized by our company, so that's our fault.
Do I understand this correctly? Are you saying you removed that root password, such that it wasn't possible to log in with another (but different) root password?
Or are you saying that you merely changed it, to one the customer no longer knew, but was the same password across all of your install base, for every customer?
How would that be any improvement, if the latter?