I guess the demise of XP is still a long ways off. If there were no XP users remaining, could there still be enough hackable computers to create a large enough botnet?
Considering a lot of intrusions happen via the web browser / plugins installed in the web browser (flash/java come to mind right off the bat), I don't think XP being retired has anything to do with future botnet sizes.
it's a coktail,you cant only blame flash or java,the browser and the os running these stuff shares some responsibility.
Exactly how is the OS supposed to stop an exploited browser from doing anything malicious? Even if you have strict access controls like SELinux, that won't stop a browser from participating in a DDOS attack and changing settings like cache or homepage to get reinfected next session. And if you don't have strict access controls, like 99% of desktops, the exploited browser can freely install all the user-mode malware it wants. So XP vs. not-XP is completely meaningless at this stage.
Even if everything was up to date, you still can't make sure that you don't get infected. The common hobby for kids these days: finding and writing exploits
A lot of these types of attack use amplification attacks (https://www.us-cert.gov/ncas/alerts/TA13-088A), often a carelessly-configured time server or name server, where only a small number of hosts are needed to wreak havoc.
Is that really a correlation? Have we seen a decrease in zombie counts as XP machines attrition out?