Internet-connected devices being sold to the public need to be regulated to encourage good security practices. The mere fact that they are internet connected means they have all the tools needed to be used for a distributed network attack. With potentially billions of them available, with little monitoring, having poor security practices will make them an incredibly attractive attack vector. In fact, they are already being used as such. The manufacturers are the only people in a position to prevent this. The regulatory atmosphere needs to change to either make the manufacturer liable for such attacks, or to tax them to create a fund to compensate victims of those attacks unless the manufacturer commits to regular updates and demonstrates good security practices.



