You're right that they should be liable, but pragmatically it's maybe too much of a risk for smaller companies to face some potentially frivolous lawsuit for millions of damages supposedly caused by a ddos originating from some of their devices or something.
Surely the right idea in principle, though. I'm just not sure how realistic is it to implement in a smart manner.