Earlier quoted context omitted.
Offering a layperson NAS buyer a self-signed cert is not "secure by default" even if browsers did accept it.
Would it be less secure than unencrypted HTTP?
But if you want "secure by default" then neither one is acceptable.