I can't quite put my finger on it, but there's something troubling about this.<p>How was the "sinkhole" implemented?<p>Did they just block ssh out of some countries?<p>Are they looking inside packets to tell the difference between the automated scanners and legit traffic?<p>Does Cicso own an ISP?<p>Who are "some other large ISPs"?