@tillshadeisgone I'm not sure you have this right. What you're choosing is a world where you have to yell at every individual who ever tries to federate from outside of mastodon. There's nothing special about this one guy. Somebody else could try the same thing tomorrow. And the day after that. And you don't have control over any of them.
@polotek @tillshadeisgone You're right about that. The ideal solution would be if instance API users had to do delegated authentication via OAuth2. Then anyone could build whatever they wanted, but data would only move around with consent. From there you could elaborate to blocklists, sensible defaults, etc.