Regular folk need to learn how to protect their IoT devices. Because they underestimate the power of a botnet consisting of millions of those devices the following occurred

A massive UDP attack sized at 11 and 1/2 terabits was executed at an undisclosed cloudflare client. According to cloudflare the largest DDoS attack mitigated to date

The reason why I deliberately say that **regular folk** need to learn how to do this, is because they can just go into a shop, get any IoT device, give it power, disregard reading the manual, where they warn you to change the default user ID password combo to something unique, and just use the device. There are oblivious to the fact that such a device, can be weaponized and used in army of other such devices.

They are unaware of the fact that others can look straight into their homes, their bedrooms, the rooms where the vulnerable children are, their vulnerable elders are and put them at risk for countless negative things.

Everyone knows that there are a search engines to find cameras in the global UDP IoT network matrix which are open with default user IDs and passwords

It's because of this deliberate ignorance by regular folk, such bot networks can proliferate and even be expanded exponentially

https://x.com/Cloudflare/status/1962559687368593552

#DDoS #InfoSec #DenialofService #networking #BlackHat

@Dendrobatus_Azureus personally, I think it's high time that #ISPs will force customers to take #ITsec seriously and terminate connections upon abuse reports.

Not that I'd take #AbuseReports by #RogueISP|s like #CloudFlare serious anyway but I've yet to find any #ISP that doesn't allow them to terminate services at any time without warning if the services are used against their ToS and every #B2C / #consumer ISP explicitly bans #DDoS, #malware distribution and #hacking in said Terms of Service.

  • And yes I've seen cases where ISPs (most notably #DTAG) did terminate connectivity following a malware infection and #Spamming from a consumer's #DSL line.

Sounds harsh but #LackOfAccountability & #LackOfConsequences got us here!