This is HN plenty of us host servers at home and understand the obviously true fact that you can't really stop it forever.
But that obviously isn't what we're talking about here. We're talking about a massive multibillion dollar corporation breaking the rules of a community project they joined by committing a Jr Sysadmin grade fuck up and ghosting the people who's infrastructure they have now placed in the crosshairs of serious, enterprise grade automated vulnerability testing from a company who might now inadvertently be committing a felony.
That's a bit different than getting a few dozen lazy hits a day because some botnet got to your IP in the Shodan and saw the Plex port open.
I don't disagree with you, I have tons of things that have public interfaces (as mundane as a fully patched wordpress where the wp-admin login is accessible to external blog writers), we get tens of thousands of random shit anything per day. But the problem here is that Tesla is treating NTP pool operators like they are their internal infrastructure. Also because the attribution of the 'attacks' is fairly well known.
I don't go complaining on the internet about the absolute shitflood of compromised routers on broadband ISPs in Indonesia probing my stuff 24x7x365 because I know it would be futile. But if I found one specific american company that was repeatedly probing my stuff all the time? Maybe I'd escalate it.
I don't actually believe the claims of this blog. A driver for a monitor from Windows update allowing mcafee antivirus and/or other programs to be installed automatically? I think more details should be shared. Also contains a long rant about EDID which I think is unwarranted.
It does sound totally ridiculous. Sadly it may not be. Previously discussed: https://news.ycombinator.com/item?id=48956688 "LG monitors silently install software through Windows Update without consent".
You can argue if it actually installs the software or just nags the user to install it, but neither are things microsoft would allow a monitor "driver" to do if they had any integrity.
An install of Windows 11 from MSFT-provided media on an HP desktop PC earlier this year resulted in a ton of HP driver-related crapware on the PC. Windows Update will happily download drivers and user-mode software the driver manufacturer flags as being related.
There is a Group Policy setting under Computer Configuration / Administrative Templates / System / Device Installation / "Prevent automatic download of applications associated with device metadata" that seems to curb most of it, thought I still ended up with a user mode app related to the audio driver.
In this case there is a two phase staleness check. The bot marks it as stale and it is correct to "bump" it if you think it is still important. The nixpkgs repo works the same way. I think it backs off from adding stale again as it gets bumped.
I'm not saying it's a perfect solution but for projects that deal with large amounts of issues it's workable.
They should just utilize the old joke about hiring: immediately throw away half the tickets, because you don't want to work on an unlucky ticket.
It'd save the run around and have the same ultimate effect. Or, we could properly work on tickets instead of making the gate "has enough time to follow up on this 14 days later"
reply