also they are in a tough spot, because if they limit the download of the most popular images, they limit their own basic usability, and those images happen to be almost all free super-fungible stuff (alpine, ubuntu, node, redis, postgresql, nginx, apache, and all the hundreds and thousands of common stuff FOSS stuff)
tying downloads to clients requires some development, requires setting up rate-limiting, etc.
I think what they ended up doing is not a terrible outcome (require login above a certain number of pulls, plus - I imagine - they require login if an IP address pulls too much anyway), but they can't really charge too much, because setting up a caching proxy is kind of trivial.