No pwd required to log in phone

I have a new digium d50 and setup a generic sip extension.

I notice the digium only logs in if the password field is blank (in the phones config). If I set this to the secret (as displayed in free pbx), it can’t login.

how do I secure the system?

thank you