I agree this is an old thing, my firewall has blocklists and allowlists to prevent known bad IPs and allow only the countries I travel to.
But if Nabu Casa is an outbound VPN, then my blocks won't work. I'd need them to block
Either way it would make sense for HA to also use some crowdsourced blocklists as a 2nd level defense