Stress testing your own site like the article shows isn't criminal intent. There is legitimate market demand to understand if a service you are running can properly withstand and filter out either large mounts of legitimate and illegitimate traffic.

Wouldn't a legitimate service for stress testing your own site ask for proof that you own the site?

I mean what makes a ddos service legitimate? Plus security is an endless cat and mouse game and asking the cat what the best way to catch a mouse is may not reveal the same information as asking the mouse how they evade the cat.

There might be too much friction to get someone working for a site to be able to prove it which will reduce sales. It's simpler to just use the legal system to enforce it by putting it in the terms of service.