I'm all for supporting innovation and community services, but I think author is not mentioning other possible causes, like DMCAs, malware and spam (including unintended), which could have damaged the reputation. I just wonder why MIT didn't give more time to move and why it doesn't provide a replacement in eg cloud credits.
Many years ago in a past life, I worked on the network security team at the University of Chicago. We had a similar policy (and they may still for all I know) of just being able to requisition publicly routable IPs and run whatever you wanted on them with no default firewall rules applied at the border. Not for nothing did we call this a "target rich environment". For all of the cool things I got to do (troubleshoot…
These are two separate things.
There is no security difference between "route port 80 of one of our public IPs through to my NATted address" and "open port 80 for my public address".
The public addresses are easier to administrate, troubleshoot, log, etc.