OK. One OEM (I don't remember who, they make TVs and the like) took our BSP and just... sent it out. To millions of devices. Tens of millions of devices. However many TVs there are.
We had just added a TURN implementation to AllJoyn and set up a dev server. Not literally a small machine under someone's desk, but basically that. Maybe a two vCPU VM.
The DDoS was _very_ distributed. The DNS requests knocked Qualcomm off the air.
So we made that an opt-in compile-time feature for all BSPs going forward.