I've started using a HAT running the TINFOIL distribution, then I've configured ingress with request token validation. I bill everyone around me on a per-request basis for UNLOCK calls to their car. I've found the system works pretty well at keeping unwanted GET requests to my MIND database by various bad actors.