Just because the idea of net neutrality exists doesn't mean it's true. I'm sure there's a specific context for it, and 'security' is not that context. It was about data/packet prioritisation wasn't it? Unrelated to security.
Trying to restrict things to end-users is the total opposite of that. The common addresses everybody gets automatically are the thing you're trying to allow. Address reputation is pointless because residential customers get dynamic IPs and the reputation you're trying to record for some IP address can get swapped with a different customer at any time.
It also feels like a description of the perfect camouflage to facilitate doing bad things: "don't block them because you might block an innocent bystander". Putting innocent bystanders in harms way sounds like someone else is the bad guy, not the person doing the blocking.
The problem being that attack traffic is disproportionately coming from devices that are compromised, which is already illegal, and you can't fix that by making it harder to use residential proxies for things that are legitimate, like sharing IP addresses between real users so they can't be used as a personal tracking ID.
> It also feels like a description of the perfect camouflage to facilitate doing bad things: "don't block them because you might block an innocent bystander".
Cloudflare promotes putting your site behind Cloudflare to inhibit censorship, because then the censors have to block their entire service (which is half the internet) to block anything. It's not always a bad thing.
> Putting innocent bystanders in harms way sounds like someone else is the bad guy, not the person doing the blocking.
If there is an alleged thief on the subway and you respond by lobbing a grenade into the subway, there is more than one bad guy.