I actually must confess I have never had to proof my code against a malicious future owner. From a Lawful Neutral standpoint, not allowing any API operations to a non-ToS-consenting user is perfectly normal. It takes an actual safety-related designer to provide a fire escape.
no subject