Article
Security & Privacy

Why the DDoS attack happened and what can be done to prevent more episodes

DDoS attacks still exploit insecure Internet‑of‑Things kit. Here’s why that happens and practical steps households and businesses can take to reduce the risk.

by Whatsnew Newsroom

Distributed Denial of Service (DDoS) attacks — where many devices bombard a target until it becomes unreachable — haven’t gone away. What changed is the pool of devices attackers can recruit. Internet‑of‑Things (IoT) kit such as network cameras, digital video recorders and smart appliances are full‑time internet‑connected computers. When they’re poorly secured, criminals can turn them into a botnet that floods websites and services with traffic.

Why IoT devices make effective DDoS bots

Several recurring weaknesses make IoT devices attractive to attackers:

- Default or hardcoded credentials. Many devices ship with simple default usernames and passwords that owners never change. Some even have credentials baked into the firmware so they can’t be changed easily. - Unnecessary remote services. Older devices often expose services such as Telnet or insecure remote administration by default, providing an easy entry point for attackers. - Poor update practices. Vendors don’t always provide timely firmware updates, and many owners do not apply updates when they are available. Unpatched software quickly becomes an entry point. - Unencrypted traffic. If devices transmit credentials or control messages in the clear, they’re easy to intercept and hijack. - Weak home networks. Poorly protected Wi‑Fi or unsegmented networks allow a single compromised device to reach other local kit and spread an infection.

Notable botnets in the past have deliberately targeted these weaknesses to build large armies of compromised devices and launch high‑volume DDoS attacks. The result is not just annoyance and downtime; when critical services rely on the same infrastructure, outages can have real economic and safety consequences.

What you can do to reduce the risk

Household and small business owners can make a big difference with straightforward steps:

- Change default passwords. Always set a strong, unique password for every device. If possible, use a password manager to generate and store them. - Disable unused services. Turn off Telnet, remote administration and other services you don’t need. If a feature isn’t essential, disable it. - Apply firmware updates. Check devices for firmware updates and enable automatic updates where available. If a device hasn’t received updates from the vendor, consider replacing it. - Use separate networks. Put IoT devices on a guest Wi‑Fi network or a dedicated VLAN so they can’t directly access your main computers and phones. - Fortify your Wi‑Fi. Use WPA2 or WPA3 encryption and a strong Wi‑Fi password. Avoid WEP or open networks. - Minimise exposure. Avoid forwarding ports from the internet to IoT devices unless strictly necessary, and disable UPnP if you don’t need it. - Buy sensibly. Choose manufacturers that publish security updates and make it easy to change credentials. Check reviews and vendor security policies before you buy.

Organisations and internet providers also have a role: better default configuration, regular updates, safer supply chains, and services that detect and mitigate large‑scale DDoS traffic help reduce the overall threat.

IoT brings great convenience, but it also brings responsibility. Secure individual devices, segment your network, and favour vendors who take security seriously — those simple measures substantially reduce the chance that your kit will be pressed into service in the next botnet.

by Whatsnew Newsroom
whatsnew. APPS · WEB TOOLS · SECURITY · AI

Know what’s new.

The useful side of the internet. Covered properly.

Set as preferred →

Related Stories