There are defenses, and there are companies that offer DDo S mitigation services for hire. If the defenders can increase their capability in the face of attack, they win.

What was new about the Krebs attack was both the massive scale and the particular devices the attackers recruited.

Apple does it just as regularly, but not on a fixed schedule. The market can't fix this because neither the buyer nor the seller cares.

But the only way for you to update the firmware in your home router is to throw it away and buy a new one. This isn't true for all of the embedded Io T systems. Think of all the CCTV cameras and DVRs used in the attack against Brian Krebs. Their devices were cheap to buy, they still work, and they don't even know Brian.

Even though the source code to the botnet that attacked Krebs has been made public, we can't update the affected devices. Already the banking industry is dealing with the security problems of Windows 95 embedded in ATMs.

Microsoft delivers security patches to your computer once a month. This same problem is going to occur all over the Internet of Things.

This isn't true of embedded systems like digital video recorders or home routers.

Those systems are sold at a much lower margin, and are often built by offshore third parties.

Last month, he wrote about an online attack-for-hire service that resulted in the arrest of the two proprietors.

