Yes, it says somewhere on the site that it uses soundwaves to share the initial key with your device.
But that's NOT an excuse to make the device depend on the Mobile ecosystem.
If it can play a code on the speaker, it can just talk. In English. Via thirty-six audio files: a.wav, b.wav, ... 9.wav. Ok, thirty-seven recordings--can't forget welcome_to_your_new_router_your_key_is.wav. :)
I'd wager that whatever they're doing, it's far more reliable than reading out English letters and doing speech recognition on it. Accomplishing the key exchange might not have been reliable in all browsers.
> Is that what you really want? A wifi AP that can be configured from the web?
Uh. Yes. In fact anything else is a deal-breaker to me and I regularly buy $300+ routers.
> Because THAT's how you get hacked.
If the router admin-interface is a POS written by the same rails-developers who leave delete operations on GET links, sure. I don't though, and I think the OpenWRT developers would take offence at such a blanket-statement like that.
But let's take your statement at face value: Web-based interfaces are inherently unsafe. Should we shut down all web-applications then? Should web shut the entire web down? That's the logical end of your extreme line of thought after all.
Bah! What's wrong with my Thinkpad?