Hard-coded IP addresses for access control are a bad security practice because IPs can be spoofed, shared, or reassigned. Internal IPs may change, and IP-based control provides no strong authentication mechanism. This creates a false sense of security and can be easily bypassed by attackers.