On October 21, 2016, large parts of the internet stopped working for people on the US East Coast. Twitter didn’t load. Reddit, Netflix, Spotify, GitHub — all flickering or down. Nothing had been hacked in the way people imagine hacking. No database was stolen. The attackers went after Dyn, a company most users had never heard of that ran DNS for a lot of big names, and hit it with three waves of traffic from a botnet.
The part that should have been the scandal, and mostly wasn’t, is what the botnet was made of. Not compromised servers. Not a clever browser exploit. It was made of home security cameras, digital video recorders, and routers — the cheap plastic boxes sitting in people’s living rooms and small offices. Hundreds of thousands of them, taken over and pointed at Dyn at the same time.
And they weren’t taken over by anything sophisticated. Mirai got in by typing the factory-default password.
It Logged In. It Didn’t Break In.
Here is the entire clever part of Mirai, and I want to be precise because the lack of cleverness is the whole story. The malware scanned the internet looking for devices with an open Telnet port — port 23, and its cousin 2323. Telnet is a remote-login protocol from 1969 that sends everything, passwords included, in plaintext. It has no business facing the internet in 2016, and yet millions of consumer devices shipped with it open.
When Mirai found an open Telnet port, it tried to log in from a hardcoded list of 62 username and password pairs. admin/admin. root/root. root/123456. support/support. The default credentials that manufacturers stamp onto identical device after identical device and never force anyone to change. If one of the 62 worked, the device was now a bot. It would report home to a control server, wait for orders, and in the meantime scan for the next victim.
That’s it. That’s the attack. No memory corruption, no zero-day, no privilege escalation. The devices were doing exactly what they were built to do — accept a login with the credentials they came with. Mirai just knew the credentials, because everybody did. They were in the manuals, printed on stickers, indexed in search engines.
Why the Devices Couldn’t Say No
You can’t blame a webcam for having a password. You can blame the entire economic structure that put that password there and made it impossible to fix.
A $30 IP camera is not a computer someone administers. It’s an appliance. It ships from a factory — often a white-label board that a dozen brands rebrand — with a default login baked into firmware, Telnet enabled for the manufacturer’s convenience, and no update mechanism anyone will ever use. The person who buys it plugs it in, sees video on their phone, and never touches it again. There is no patch Tuesday for a doorbell camera. There is frequently no patch at all.
So the vulnerability wasn’t a bug. It was a business model. Every party in the chain had a rational reason to skip security: the chip maker sold reference firmware with Telnet on because it was easier to debug; the brand shipped it unchanged because changing it costs money; the retailer competed on price, not on whether the thing could be conscripted into a botnet; the buyer had no way to evaluate any of this and wouldn’t have paid more if they could. Insecurity was the cost-optimized default, and it scaled to millions of units. Mirai didn’t find a hole in that system. Mirai was the system, read back to us.
The Source Code Went Public on Purpose
A few weeks before the Dyn attack, in late September 2016, someone using the handle “Anna-senpai” posted Mirai’s complete source code to a hacking forum. This is not what you do if you’re trying to keep a weapon. It’s what you do when you want deniability: once the code is public and everyone can run their own copy, no single botnet’s traffic points cleanly back at you.
It worked as camouflage and backfired as containment. Publishing the source turned a single botnet into a template. Within weeks there were dozens of Mirai variants run by different people, each scanning the same pool of defenceless devices, sometimes fighting each other for the same cameras. The Dyn attack drew on this larger, splintered ecosystem. You cannot recall source code. Once “here is how you build an IoT botnet” is a downloadable file, it is a permanent feature of the landscape, and Mirai’s descendants are still scanning port 23 today.
The people behind the original were caught, which is its own small irony. In December 2017, three men — Paras Jha, a Rutgers computer science student who was Anna-senpai, along with Josiah White and Dalton Norman — pleaded guilty to federal computer crime charges. The motive was almost aggressively unglamorous: it started as a hustle around Minecraft servers, using DDoS muscle to knock rivals offline and to sell protection against the very attacks they were launching. They cooperated with the FBI, and none of them served jail time — probation, community service, restitution. The largest DDoS event the internet had seen to that point traced back to a business dispute over a video game.
The Two Lessons Nobody Fully Took
Mirai taught two things, and the industry half-learned each.
The first is about DNS. The Dyn attack didn’t break the sites people couldn’t reach; Twitter and Netflix were up the whole time. It broke the directory that tells you where they live. Enough companies had outsourced their DNS to a single provider that taking down that one provider took down all of them at once. This is the same shape as every big outage since — a shared dependency nobody thinks about until it fails, and its blast radius is every customer at the same instant. We keep centralizing onto fewer providers because it’s cheaper and usually more reliable, and we keep being surprised when the usually holds right up until it doesn’t.
The second is about the devices, and it’s the one we’ve barely touched. The number of internet-connected appliances has gone up by an order of magnitude since 2016 — more cameras, more thermostats, more speakers, more things with a chip and a default password and no update path. There have been laws since (California and the UK both banned universal default passwords on connected devices), and those help at the margin. But the fundamental economics haven’t moved: the person who bears the security cost is not the person who pays for the insecurity. Your camera getting conscripted doesn’t hurt you. It hurts Dyn, and everyone who depended on Dyn.
Mirai was not a story about brilliant attackers. It was a story about a world full of devices that would let anyone in who knew the password everyone already knew, wired to an internet that assumed they wouldn’t. The attackers weren’t the interesting part. The interesting part is that the doors were open, and they still mostly are.