@mikedev @streams Even if properly implemented, authorized fetch is easy to bypass. For example, one can create a puppet actor on a different domain.
Instance blocks are only effective because setting up a new domain costs something (money, time). However, someone like Meta may create a lot of domains and a lot of actors, so the only real protection against them is allowlist federation (not necessarily a literal allowlist, it could be some complicated web-of-trust mechanism).