Maybe we should just ddos these endpoints, they don't deserve anything better.
Is anyone MITM-ing and publishing the data these devices are sending? It would be nice to reverse engineer and document their APIs. Somebody needs to be watching the watchers.
DDoS protection is surprisingly challenging - usually it's relegated to a CDN provider, but that would be more difficult when the actual consumers are the same people most likely to be hosting botnets.