It would be a comforting feeling to have a bit more authentication security. How difficult would it be to add a field in the config page to change the username? It would also be nice to have a third form of authentication like an allowed phone numbers list (not good for tablets) or a salt the user can supply in the config that has to match in the ap.
set username
set password
set salt
Or perhaps an email or text message text message that needs to be responded to upon setting up ap.
Just an idea. More security is a good thing.