Quote from: Frank Hart on February 07, 2024, 15:21:10The notion that connected "smart devices" are a security risk to a normal home is fake. Every standard home router has what's called a "firewall" that prevents arbitrary ingress unless something has gone profoundly wrong.
This article isn't talking about ingress into someone's home*, it's talking about egress from millions of homes to the Swiss website.
My firewall is good enough that I can create rules such that {IoT device} only has access to communicate with {IoT provider} such that this DDoS wouldn't work even IF the device got infected.
*If you're wondering how the toothbrushes got infected when they were behind people's home firewalls ... the way these things connect to their "smart" services is super sloppy and lazy, and if someone's DNS is poisoned or some other some situation, that could give the attackers their "in." And considering the general lack of understanding when it comes to networking and security, I wouldn't be surprised to find a large swath of home routers misconfigured such that they aren't providing the protection they're technically capable of.