I agree with this. Spread it among counter-attack, bricking bounty, official program, encouragement to private hackers, whatever routes can be taken - but yes, brick such devices.
I wouldn't suggest this in a vacuum, but given the every-way-is-pain situation we're in, I think it's here defensible to suggest that any IoT device which CAN be remotely bricked SHOULD be remotely bricked. It is vulnerable and abusable. Such a device is "rabid" and should be put down.
Bricking
I wouldn't suggest this in a vacuum, but given the every-way-is-pain situation we're in, I think it's here defensible to suggest that any IoT device which CAN be remotely bricked SHOULD be remotely bricked. It is vulnerable and abusable. Such a device is "rabid" and should be put down.