I'm surprised that "security by obscurity" is touted as a way reduce attacks. This is almost guaranteed to lead to less diligence in the code — and more risks.
I wonder how much that has to do with human nature thinking "well this is obscure" so then they don't secure it as if it was 'customer facing' or less 'obscure'.... and thus leave it more open than ever.
I knew a place that assumed such things, crazy insecure. They also played the "well this shouldn't be exposed to the internet" game as well.
> In recent years, security through obscurity has gained support as a methodology in cybersecurity through Moving Target Defense and cyber deception.[9] NIST's cyber resiliency framework, 800-160 Volume 2, recommends the usage of security through obscurity as a complementary part of a resilient and secure computing environment.