Internet of Things botnets: You ain’t seen nothing yet


What's really the difference between HTTPing to port 80 and Telnetting to it?

I agree, up to a point, but you shouldn't be allowed to do that either. It ought to be https on 443 and the only thing it will present you with there is a login page.

I get why it wants a "non web" port open, so it can take commands from things that script automation, but if you're going to do that then there ought to be key exchange first.

