Earlier quoted context omitted.
Is logging into a VPN in 3 seconds and starting to work not "right away" enough?
Maintaining a stateful VPN connection is much harder than making a stateless HTTP request.
I see what these guys are trying to get at - its essentially how I run distributed services for my small business, but having a VPN in front of those is still a more secure option. VPN should not mean the keys to the kingdom and should indeed be restricted to a subset of explicitly exposed services.