Security groups
Cloud network rules are trivial to widen and very difficult to narrow again.
Opening something to everything unblocks whatever is failing right now, which is why it happens during an incident or a deadline. Closing it later requires knowing what depends on it, which nobody recorded. The ruleset accumulates the same way firewall rules always have, just faster.
Checked against the primary source.
