At a hazard, this came up during architecture review for plugins and has now been implemented, which is good. (Also, botnet membership is not the only risk; exposure in an internal network and being used for lateral moves or persistent footholds inside an internal network that has bridges to the outside somewhere is another risk scenario)
Somewhat related: Gina Häußge is fighting to keep people from exposing Octoprint to the internet unsecured, yet you can easily find many instances that are at risk if you know where to look.
I'm pretty sure if someone were to sponsor a thorough security review of DSF, that the results would be more than welcome by the Duet3D team.