This is not a popular opinion and it often gets dunked on reflexively, but I truly believe the default is low-trust. We are one evolutionary step away from chimpanzees, with barely enough "society" grafted on to our world, which mostly doesn't function. You need to assume you are under potential attack at all times and be prepared to defend against it. Whether it be a physical attack, social engineering, scams, advertisements... in cyber-space and in meat-space. Any other security posture, long term will eventually open you up to a breach by an adversary.
I think it's a tiny minority of people doing this, with the Internet amplifying their reach.
This world runs on trust. For example it's extremely easy to shoplift, yet the vast majority of people don't. Because people are not like that. It's easy to forge things, yet most people don't, it's easy to snatch and grab random objects from people or places, yet, people don't.
The next time you are out, think like a criminal and see just how much stuff you would be able to do, yet you don't, and neither does anyone else.
It's a tiny minority who do abuse that trust.
(And we are not "one evolutionary step", we are several orders of magnitude steps away from chimps. In intelligence chimps are more similar to dogs than they are to humans, chips are smart - for animals. In comparison to humans they just aren't.)
And IMHO it's better that way, because the alternative --- which some seem to be slowly encouraging us towards --- is dystopia.
Personally I don't really know how to draw a clear line between acceptable and unacceptable here. Sure we can assume intent when requesting a users API from a standard WordPress install or plugin, but can we really say what the person's intent is? There are white hat hackers after all, and a law blocking this would almost certainly stop anyone interested in discovering these vulnerabilities and making them known before someone with bad intent finds them.
I'm always very hesitant to see any top-down changes trying to change public sentiment though, whether by some kind of intervention to change norms or through law. Norms and laws should reflect, rather than coerce, public opinion. If a majority of people would, of their own accord, agree that hitting common API endpoints on servers publicly connected to the internet is too dangerous to be allowed, I guess we could try to draw a line between that and hacking or penetration testing with good intent.
Short of that though, is it really our place to convince people that this is wrong? Sure we can absolutely do a better job of raising awareness of what's going on, but at least to me awareness of the facts should be the extent of it. People can make up their own decisions on whether or not something is okay, or if its bad enough that we need to further empower the government to enforce more laws.
The FBI is responsible for super serious and intrastate crimes like terrorism, kidnappings and trafficking. Those resources get redirected to policing copyright violations at the behest of the MPAA and other IP orgs.
ICE resources are redirected from border safety to protecting profit margins impacted by knockoff goods.
Whatever entity gets setup to address your concerns will eventually be captured by major corporate interests.
I suspect this is one of the overall effects that have come about on account of individuals judging the inequity across the world.
an authoritarian global government and cameras you aren't allowed to turn off in every room of your home
This shouldn't be hard. If we can't fix that then good luck tracking down bad actors on the interwebs
I don’t have an answer. This normal isn’t OK. I don’t know what to do about it though.