it would be trivial for them to not DDoS and yet they keep doing it.
if they were calling Lemmy APIs directly they would significantly reduce the load they bring to our service. if they were speaking ActivityPub they could even get the content delivered to their front door directly via federation.
they don't care that they DDoS websites. they don't care about optimizing for how certain types of websites are built, to reduce impact on third parties. the only language they speak is DDoS.
they intentionally spoof legitimate browser user agents and cycle through massive ranges of IP addresses. they have enormous pools of IPv4 addresses available that allow them to only use each IP for a couple of requests before cycling to the next one, which is yet another way they evade detection, as they are bypassing any rate limits we have configured that way.