As insecure IoT devices make large-scale DDoS attacks more potent, the Internet community should work to adopt standards and tools to prevent these attacks
John Gilmore, an American entrepreneur and civil libertarian, once famously quipped that “the Internet interprets censorship as damage and routes around it.”
Context & Ripple Effects
This piece lands mid-arc in a fast-building story: a month earlier, Motherboard laid out how the rise of connected devices makes cyberattacks capable of real-world physical damage, and two weeks before publication, operators of critical Internet infrastructure reported probe-like DDoS activity at a scale suggesting state actors. The article's argument is the defensive counterpoint — since insecure IoT hardware is what amplifies these attacks, the fix has to be standards and tooling adopted by the Internet community itself.
First-order effects
- Owners of poorly secured IoT devices — printers, DVRs, cameras — see their hardware conscripted as DDoS ammunition without their knowledge or consent.
- Network and infrastructure operators bear the immediate cost, absorbing attack traffic whose volume scales with every new insecure device shipped.
Second-order effects
- The failure of voluntary patching strengthens the case Motherboard presses in its follow-up coverage that only government regulation can force manufacturers to secure unpatchable devices.
- Attackers shift from compromised hosts to abused protocols themselves — by 2019, the WS-Discovery protocol used by printers and DVRs was being regularly weaponized in large DDoS attacks, showing the problem outlives any single botnet takedown.
Third-order effects
- If standards adoption lags, security shifts from a product feature to a procurement and liability question, with distributors and carriers pressured to filter or refuse traffic from known-insecure device classes.
- The pattern points toward a split market: regulated, securable IoT for critical deployments versus a long tail of cheap unpatchable devices that permanently lowers the cost floor for large-scale attacks.
The trend: The unpatchable IoT installed base is turning consumer devices into commodity DDoS firepower, steadily converting a technical nuisance into an argument for mandatory security standards.