Earlier quoted context omitted.
Take a look at Axis Secure Remote Access solution for a way to avoid port forwarding (with its issues) and still get remote access, basically no configuration at all except from actually initially adding the camera to your site. Only works on Axis cameras though with Axis client software I should mention.
That's essentially using their servers as a middle-man. Which raises the question: why would one trust Axis to build servers that withstand attacks but not to build cameras that do the same?
Regarding servers vs cameras: To oversimplify; servers can have exponentially more capacity. Either how, in this case, the traffic is encrypted in each end so there's nothing to be done by "the middle man servers", they can't decrypt anything cause they don't possess the keys.