A snippet from the article on the residential IP's:
"Furthermore, we conducted realtime device fingerprinting when we captured each IP address. And we have successfully identified the device type and vendor information for 547,497 IP addresses. What surprised us is that 237,029 of them turned out to be IoT systems, such as web camera, DVR, and printer."
This was probably the beginning of the end of Facebook, at least for me. I started interacting with Facebook much less and started to forget about it, because I didn't want everybody to see how addicted I was to Facebook. The same happened with Instagram when everybody was able to see what I was liking. This is turned off now, but the damage was already done, I became too paranoid to get addicted to social media again. I'm clean now for almost 2 years, thank you.
It's easier because the current tools of building the planes are not made for this new type of planes. Update the tools and building this new type of plane will be easy too.
FTR, they say: "As you can see, the ascp client performs over 200x faster than FTP, and can download the whole file in 9 seconds. It’s pretty magical." But the example shows MB/s vs Mb/s. It's not over 200x times faster, but about 17 times faster.
You could generate a certificate for each user, but without the duplicate-cn option a user is only allowed 1 connection to the same server. You can also use username/password authentication instead of certificates, also in this case you'll need to set the duplicate-cn option to allow multiple connections from the same user to the same server, because in this case you use the option username-as-common-name and the CN (common name) will then be the username.
Using a database for user authentication, you could write a script to fill the database with some usernames and passwords.
Or create a webfrontend for users to register their own usernames and passwords.
May I suggest to turn off logging for your own server too? :-) Anyone with physical access to the server can access the logs, maybe even when the disks are encrypted, I can imagine someone with the right knowledge can extract the key from RAM on a running server:
"Apple says an elaborate rotating key scheme will soon let you track down your stolen laptop, but not let anyone track you. Not even Apple."