Mechanical Turk is Amazon's Google Reader. I had to write a whole guide[1] on not getting screwed over by scam requesters because all the tools for it don't exist as part of Mechanical Turk. I don't think Amazon has touched the service since they launched it.
The only one I've thought of since writing this is to have a separate AWS account and link it as a sub account for billing. Solves someone shutting down your main servers, but still means they can spin stuff up / use lots of cash. This would be a massive pain for us as we'd loose our worker pool. I could do it the other way, move our infrastructure to a new account...but that sounds equally painful.
A new account doesn't have all AWS services enabled by default, so the impact seems minimal to start with. Not sure if you can lock this down further as I haven't looked into it.
Or have it charged to an entirely separate card, one that gets reloaded with money every month to cover planned MT expenses. Annoying, but the safest option, I suspect
Well this is the same for most services, I've seen - including MobileWorks? If you register as a worker and you can accept tasks, if you meet the requirements.
It's avoided to some extent by us due to the way we issue training / challenge work before any actual work is given to new workers.
Not quite: in MobileWorks, work is assigned to private workers, so nothing is public. The same goes for CloudFactory, TaskUs, and the other non-marketplace crowd platforms.
You're right that challenge work does a reasonable job of screening tasks from search engines, though!