OK so I can see how it violates standards. How many of the millions of users that send traffic through EC2 does this affect however? I can see how they would be reluctant to mess with Firewall rulesets. Even if it they only apply it to new users that would mean fragmentation ... Keep it simple stupid. Again it depends on how many users this affects and from the sounds of the blog post - vanishingly few