The DSL provider in my area sets up customer's wireless networks with their home or mobile phone number as the password. If you know that number or can look it up in public records then you're in. If you can't find it maybe use a dictionary pertaining to the area code of phone numbers and then you're in. When the protocol changes to something more secure, the ISP's customer will still be as insecure as they always were.
That's not as bad as deriving password and SSID (Provider-$generated_number) from the MAC address, it didn't take much for somebody to reverse the algorithm from the bootloader and make various programs to calculate the few possible password from SSID