Earlier quoted context omitted.
"anything inside my home network from anywhere on the internet" doesn't sound much like robust access controls. I wouldn't trust the horrible default passwords and lax security built into most devices for home use to be exposed directly to the Internet even with a firewall.
Robust access controls would be things like certificate auth, MFA is cool, fail2ban is good, maybe throw in some roles there; whatever floats your boat. So yeah, your security model should involve not using default passwords and not using devices that have unchangeable default passwords. Again, people are depending on something that isn't really designed to provide security to provide security. Devices that have horr…
Some people just want their lightswitches to work.