Or you could just choose a strong password / disable password auth? Why would DO side with anonymous abuse reporters over their customers?
And DO doesn’t have to side with individual abuse reporters. If they cared, they could spend a fraction of an hour setting up the knock-knock software on one of their own servers, and generate their own list of abusive IPs. They just don’t care.