That being said, they’re absolutely right that these broad, automated blocks aren’t acceptable for the internet as a whole - especially when a ruling is applicable regionally or globally. Blocking an entire IP range or service provider because of a handful of bad actors on their service is incredibly excessive, akin to barricading off an entire neighborhood because one apartment is a crack den, i.e. stupidly disproportionate. If countries are having an issue with a company routinely and willfully allowing bad actors to prosper, the solution is simply to bar that company from operating within their jurisdiction commercially.
Yet the IT dinosaur in me reads that statement above, and I ultimately find myself back at where I’ve been for years: for a globally distributed network, the only way to effectively punish an operator like Cloudflare is to block its entire IP range, despite the harms innocent customers and users will incur. And I can’t quite figure out a way past that under the current piecemeal system of the internet and the financial incentives for consolidation and centralization.
We have to punish bad actors, but when said actor commands a significant swath of the legitimate internet, you either have to harm a disproportionate amount of legitimate traffic in blocking them, or admit they’re too big and important for a government to intervene against. The former is bad, but the latter is infinitely worse.