ELI5:
Way back in the early 2000s I was a young mid level developer and we had a SQL Server backed solution. There was a wide spread attack on Sql Server installations that didn’t change the default blank SA password. We were one of the companies that didn’t.
But, even then I knew not to have a publicly accessible database server. We just didn’t give the server a public IP address. Nothing fancy. We weren’t affected but I immediately changed the password.
Fast forward to 2018. The company I worked for was just starting to ramp up an in-house development staff led by a new CTO. Everything had been outsourced to a foreign agency. They had a publicly accessible ElasticSearch cluster. I wasn’t on the team responsible for it, but I know that the architect on the team knew better. Even though he didn’t setup the original cluster, he knew it was insecure and just didn’t prioritize recreating it inside our VPC.
Of course we got hacked and someone deleted everything in it. Then they decided to go ahead and recreate it inside the VPC. Luckily we didn’t use ES as a primary store and we were just offline all day while we ran the process to repopulate the cluster from our Mysql database.
Why do people keep making the same mistake? I was definitely not any world class software architect at 25 years old, but even I knew to be cautious about giving servers public IP addresses unnecessarily.