Hard-coded IP access control is fundamentally insecure because IP addresses can be spoofed, are dynamic (especially for ISPs), and create inflexible, brittle security. Option D correctly identifies this as bad practice. Internal IPs (A) and IP conflicts (B) aren't the core issues.