While I agree is likely secure enough, remember that cloud operators such as Aws used to be ok with making s3 buckets public by default, which did cause many issues until they finally changed that (and made it harder to make them public even intentionally).