This is the solution. Implementing auth isn't that difficult.

Oh yeah, auth itself isn't that difficult. But... auth resilient against malicious actors?