> then transferred that risk to its customers And, even less ethically, all their victims. Anybody who runs a server on the Internet knows that it will constantly be under attack by people with "sloppy and corrupt practices". Yet I have never once seen an ISP offer a reward for reporting abuse or offered me compensation for damage done by bad actors coming from their network space. Big cloud providers like Amazon and Google rake in the cash, and everyone else pays the price of building a security apparatus to keep out their riffraff. This SolarWinds exploit is just another case of SSDD as far as I can tell. There are some new bits, sure, but any arms race leads to attacks of increasing sophistication. To me, the fundamental question comes back to *why on Earth* is traffic from untrustworthy sources, especially from hostile nation states like China and Russia, treated on par with that of paying customers, never mind being allowed into build servers and other critical parts of the supply chain? I fully agree that Matt Stoller nails it in his article, at least from the bigger picture, economic incentive angle. Well worth the read. ca77dd1ba199ce6a0076197fbcbc7f3b3dab21cdeb19d695cd5e38e2a49bd100