Internet access is a privilege, and being a threat to others in this shared space should lead to said privilege being revoked until the threat is gone.
Internet access is a privilege, and being a threat to others in this shared space should lead to said privilege being revoked until the threat is gone.
They all pay their ISP a hefty "rental" fee for their crap modem. It's only fair to hold the ISPs responsible in such cases.
Yes, everyone could be more responsible about their consumption but why should that free the manufacturers from the responsibility of making competent products to begin with?
I don't know how to tell whether my router is vulnerable, or what I could even do about it. If I'm not savvy enough for your proposed rules, which does seem quite possible, I don't think most people have much hope.
It is the job of the techies to fix techie problems. When a bridge shakes beyond specs, it is the job of engineers to fix it, bridge building is not crowdsourced to society.
Car analogies are always fun, so here's one: The catalytic converter on my car is sawzalled off in the middle of the night. I drive around with the missing cat for a couple months. Then I fail a smog check, or get a ticket for loud exhaust. Is it my fault the cat was stolen? No, but I still have a responsibility to everyone else to not pollute (fumes or noise).
If the ISP supplies the router, then of course they should correct it. But if the subscriber brings their own equipment, then they take on the responsibility of maintaining it. Including replacement if it turns out not to be fit for purpose.
Not, it is a fault of thieves. And maybe a police who prefer to generate ticketing revenue rather then go after real criminals.
Car manufacturers are required to do recalls on cars that have airbags that explode rather than inflate. Even 20 year old clunkers. They widely publicize cars they think aren't actually safe anymore so customers can choose to update.
When food is shipped out to customers full of listeria, they don't say "you should have kept a full pcr lab in the kitchen and tested every bite, this is obviously the eater's fault", they flood the news with recall notices and take the food back and offer a refund. (and often are still sued because they too have responsibility).
The firewall stopped doing it's job, if it had done it's job properly the device wouldn't have been owned. Why shouldn't firewall manufacturers be required to have some responsibility when the firewall is shown to not actually firewall?
> Why shouldn't firewall manufacturers be required to have some responsibility when the firewall is shown to not actually firewall?
They should! I'm not arguing against holding companies responsible for their crap products. I'm arguing that the ISP shouldn't be forced to keep an attack vector on their network.
If a shitty home router becomes a bot in a DDOS botnet, that's not the ISP's responsibility. From their perspective, it's on the subscriber. From the subscriber's perspective, it's on the maker of that shitty router. (ISP-provided equipment is obviously different)
And it was a botnet with "hundreds of devices." That is literally nothing. People who want to live in this world where abuse emails are king and a bunch of Spamhaus type people lord over the Internet always weird me out.
https://www.justice.gov/opa/pr/us-government-disrupts-botnet...
> China’s hackers are targeting American civilian critical infrastructure, pre-positioning to cause real-world harm to American citizens and communities in the event of conflict
Edit: I agree it is important to do takedowns. Qakbot, GameOver Zeus, Emotet, Snake, etc all had actual espionage risk / were cumulatively involved in billions of dollars of theft. But this botnet seems sort of irrelevant.
Give them a remediation time of 24 hours. If that doesn't help, cut them off anyway, as that's the only thing that will force management to give their IT people actual staff and budget. Hospital IT is almost always a shitshow and that won't change until external pressure forces management's hand.
Furthermore, taking it at face value, why shouldn't this condemnation apply to the FBI first ? They've got compromised devices with the out of life software that's causing a bigger problem. So by applying that standard, they should be taken offline first. Which I'd say highlights a deep problematic assumption in reaching for the blame game, whereby some nodes start to be considered "more equal" than others.
Just a quote from a friend.
How about you start your own internet for fragile systems that can't handle the real internet? Then you can be a dictator and require remote attestation or whatever.
Yes, but a lot of the internet is on a shoe-string budget and managed by someone who DGAF, and connected to an ISP who also DGAF.
Global emissions enforcement is just about as good as global internet security enforcement. That's why the internet is full of malware and the earth is getting warmer.