Maybe in next versions they should choose 256 bits (or 160, like bitcoin) which would be the hash of a public key, an any vendor that provides a valid signature, can claim that 160 bit vendor ID. No more need for a central authority
I'm probably overengineering it, just pointing out it is technically possible