The thing is, they provided a large, under-educated user base with powerful, complex and utterly sophisticated tools.
That the attacker targeted those and not less numerous and better guarded mainstream manufacturers only pays tribute to the success of Mikrotik.
Do you think the expensive manufacturers don’t do that? I’ve seen un-configured, un-updated, EoL Cisco equipment. Small businesses get sold it because it’s “the best”, but they don’t actually need anything nearly that complicated and don’t want to pay the ongoing costs so you end up with things like managed switches being used like you’d use a dumb switch that’s 1/10th of the price.
I was in a server room a couple of years ago that looked like a Cisco museum, with some of the kit dating back to the early 2000s. When I mentioned that running a business on gear that had been EoL'd for a decade+ wasn't quite up to security best practices my contact shrugged and said they wouldn't be updating any of it in any case since they'd long since lost all of their access passwords.
https://www.cvedetails.com/product/23641/Mikrotik-Routeros.h...
Step 2: Ban IoT that doesn't meet software compliance
Step 3: Pray that the compliance standard makes any sense and that the NSA don't require backdoors or suspect CRNG.
The general public can’t distinguish between secure and insecure products, but they can read a list of products that are covered by the $0.99/month insurance plan, and anything not on that list you need the $1.99/month plan.
DDoS victims can then make a claim against the insurance companies (who own the liability arising from each IP address; ISPs can de-NAT), a court can evaluate the evidence if necessary, and the insurance providers pay out.
N.B. It’s actually experts who would be penalized most by this scheme, because if you do something like run a customized FreeBSD box, it’s unlikely to appear on the audited-device list.
The "audit" can be as simple as the insurance company running automated pentests trying published exploits and passwords.
That would still achieve the desired goal (the majority of botnets spread via well-known vulnerabilities and/or bruteforced credentials, custom equipment where manual effort is needed on the attacker's part are a minority) while allowing enthusiasts to run custom hardware.
I worked for a popular service that regularly received DDoS attacks from botnets. We had logs with the IPs of tens of thousands of vulnerable devices. If you scanned them you could see the vast majority were compromised routers, VPNs, or IoT devices. Most of them had open proxies installed and were easy to identify as compromised. For the larger ones we could reach out and get them shut down (usually). But we didn't have time to contact thousands of ISPs.
I would've been happy to forward those logs, even with verification of compromise, to an independent body that could follow up and get them shut down. Even if a small fraction of ISPs didn't comply it would still remove the majority of compromised devices. Most of the companies we contacted were more than happy to get rid of problematic hosts and acted quickly. They just didn't have the expertise to monitor for such things themselves.
It would all have to be voluntary, of course, but it could be done.
This is the type of thing that I think CERT was originally intended for, but for whatever reason doesn't seem to handle.
I wonder if there are other RBLs worth subscribing to and blocking.
As an end user with a compromised device, it might be frustrating though... but then they probably should know and do something about it.