I've come across multiple guidelines stating that AWS RDS instances should not be configured to be publicly accessible, because it is a major security risk. Example:RDS Publicly Accessible - RDS best practice
If the RDS instance is configured with a sufficiently strong and unique password which is practically impossible to brute-force, is it still a security risk? Wouldn't a strong and unique password make the instance reasonably safe, even if it is publicly accessible?