I know that SpamHaus is using this dataset as a large (at times sole) contributor to their blocklists. So corporate buyers are doing exactly what you describe, albeit indirectly.
Lack of any IoCs also makes it hard to refute or remedy. Plus I think it paints even Tor relay nodes with the same brush as malicious proxies.
Truly kafkaesque if you start getting restricted and nobody tells you why or even knows what to tell you because the sources have all been mixed and obscured.
They give you the full /64 even on vps or kimsufi(low end servers) it's just that the interface is configured with the ::1/128 by default in their cloud-init.
Their documentation about it is not consistent though, so the confusion is understandable.
reply