Earlier quoted context omitted.
This is a case study in why you shouldn't expose your self-hosted services to the internet.
Google has gone the opposite direction. I feel like throwing everything behind a VPN and pretending it is secure is a crux. Several famous break-ins over the last ten years have hypothetically been on the inside of that wall. Better to isolate services from each other limiting cross service jumping, than to build security around a single point of failure.
Service isolation alone doesn't help when my private data is potentially exposed by this exploit.