I've unironically been using this font ever since I found it a year or two ago. I find it makes it so much easier to read everything. I've even suggested it to others. It's actually a decent font.
DDOS is a pretty brute-force attack, so it isn't typically relying on a vulnerability per se. Pretty much the only way to mitigate it is to have large enough infrastructure that you can detect and filter out its gobs of spammy traffic, which no Lemmy instances (at least at the moment) can really practically have. They could potentially use a service like CloudFlare, which does have that infrastructure in place, but that can be expensive. I'd imagine CloudFlare (or a competitor) is probably the best solution they can go with, at least in the short-term.
:f