It's not done from a security standpoint. It's done as a blanket bandwidth control measure. We are aware of the advantages and disadvantages and have chosen to do this. Understand that it is far more simple, effective, and lighter on resources to do this at the web server level than individual page code level. In fact, some things are impossible from the page code level that are possible on the web server level. It's actually lighter on resources than running a bandwidth throttling and connection limiting module too, which we tried for awhile. We choose less resources, less time, and full connections and speed. So long as things remain under control, we can keep it that way and do not need to add farther hardships (There are several possible approaches).
