For mysql I just use the skip-networking option to only allow connections locally using the named pipe interface. Or just block port 3306 and only allow connections from IPs that I want to connect.
So if I make a bomb, and put "This is not a bomb" on it, then no-one will think it's a bomb?
"A complex system that works is invariably found to have evolved from a simple system that worked." -- John Gall, _Systemantics_