KrebsOnSecurity being taken down due to persistent DDoS
twitter.com
twitter.com
> I'd blame the insurance company if they dropped me the second I was diagnosed with cancer
What kind of an insurance company would target likely victims anyway?
If it wasn't clear, Krebs wasn't paying Akamai a penny. I'd assume their cheapest solutions start around 10k a month, hard to justify for a journo.
How much do you think a solo netsec journalist with only a couple of ads on his site earns?
He provides a real service. Which is probably why Akamai offered him their services for free, in the first place.
Krebs shines a light on shadows that very much don't want to be seen, much less outed. The years long level of escalating attacks against him and his site reflect this.
Still understandable that Akamai dropped that after while, despite the PR damage, especially if it affected their work for paying customers.
It's a good selector for the kind of people who'd write "Mastery of C/C++" thinking they're the same thing.
However I wound't blame IoT for all of it. What about uncountable number of vulnerable routers at home and small offices? As far as I know they may send legitimate (from ISP PoV) low traffic all day to some endpoints on internet.
Personally, I think IoT is just a buzzword coming from I don't know where. IoT has existed the moment two things were connected over a network, and this was decades ago.
>What about uncountable number of vulnerable routers at home and small offices?
"Hypothetical" cases: devices of sensitive organizations just sitting there with default configuration. FTP servers of TV stations with a genius admin making a tutorial for staff with the goddamn credentials on the "intranet page" (you have the privileges of writing the news of tomorrow, literally). Teleconference system of major company that are broadcasting what's happening in the meeting room because why not. Readable and writable remote sensing devices that are broadcasting information that matters a great deal and you could just toy with it.
All this without even brute-force or exploiting a vulnerability. Basically within the reach of any monkey who could type admin-admin.
http://webcache.googleusercontent.com/search?q=cache:http://...