Arguing that an IP address is an identity "for this case" or "this argument" has the same fundamental problem. No, an IP address is not an identity and blocking an IP address is the physical world equivalent of putting up some traffic cones on a sidewalk. You can still get to where you want to go but you now have to "walk around" or "work around" as we call it in the digital world.
The only "clear message" it sends is, "don't use that IP."
> The only "clear message" it sends is, "don't use that IP."
Are you saying with a straight face that anyone at Power thought it was a coincidence that suddenly they couldn't access Facebook from very specific IP addresses?
Then it should stop authorizing Power to do so. Why would it let the credentials work for Power unless those credentials authorized Power access? That's the problem. The simple solution is 2-factor authentication.
This is a solved problem. If you have "open access" of your web services and and access is non-disruptive, I don't know why this should be a criminal violation. It shouldn't be criminal just because it doesn't fit with your business model.
What if you tell me to stop doing it, but my friend is allowed and he types all of the commands that i tell him to type and then he sends me the data? That's why it doesn't quite make sense.
It doesn't make as much sense for a publicly accessible website and user tokens. It makes sense from a tort point of view, but not from a criminal point of view. The next step away would be for users to install an app that logs into facebook and forwards the data to the centralized server.