Earlier quoted context omitted.
Why don't we just require major providers to provide a realtime list of IPs that are attacking so that we can drop them in a block list with an expiration date of a month or so. If your computer is infected, I don't want to talk to you for a month. If it continues to be infected, I might up that to a year, or permanently ban you. It's your problem. Go fix it.
I've been on the receiving end of "Your" (dynamic) "IP has been blocked." I would greatly prefer not having my semi-randomized IP blocked because someone used it maliciously a year ago.
The problem is that ISPs whose customers are originating the attacks from don’t give a shit.
If we have to give up 1% of legitimate traffic to thwart 90% of attacks, it is a good deal.
If you and other customers complain to your ISP (or switch), eventually they’ll do something about it.
We can’t seriously keep on accepting that « thousands of compromised devices » is a fine reality for a « small botnet ».
These devices should be quarantined.