As a point of reference, I get shitloads of attacks on my server, bots trying to log in using the name "pi". I get dozens or hundreds of "pi" login attempts a day. I also get attempted logins from ...
This doesn't make a whole lot of sense. Just having a user account named "pi" is not a security vulnerability. Its making it accessible remotely with a plaintext password that is the security ...