I am reminded of Steve Kemp's 2014 post »Secure your rsync shares, please«[0], relating how he abandoned a project employing zmap[1] upon discovering numerous openly accessible rsync shares containing sensible information. His closing remarks echo the sentiment of the article under discussion here: "I considered not posting this, but I suspect 'bad people' already know..,"[0]
What can be done? Are we reduced to just securing our friends' and families' infrastructure, all the while standing by idly while others outside of our direct sphere of influence suffer the consequences of naïvety?
[0] http://blog.steve.org.uk/secure_your_rsync_shares__please_.h...
[1] A cleverly-built, fast network scanner, https://zmap.io/
[2] http://danmcinerney.org/how-to-exploit-home-routers-for-anon...