You said it better than I: There's essentially no need for putting your house on the public Internet. Private local net, maybe; home automation does have legitimate uses (though putting it on your network strikes me as massive overkill)... but as with everything else, unless you have a need to expose it out thru the firewall you have a need NOT to do so. Never mind passwords; it simply shouldn't be visible.
FWIW, industry worked thru this set of issues a decade ago. There was discussion of whether having everything on a site under IP control might make sense, to simplify wiring -- and the conclusion was "no", both for security reasons and because there was simply no advantage to making that the default.
This is a fix looking for a problem looking for a solution looking for a need.