@nprofile1q... I think it's more complicated than that. For the same reason things like Cloudflare exist, the desire is to serve content to people and legit bots, not scammers, spammers and that vibe coded AI project some dude doesn't even know is still running on a box in his closet.
Mastodon had to implement HTTP signatures for the same reason. Once you open up CORS *, you're at the mercy of the internet and it's a bad place.