> Personally I think the the idea that the LAN is some walled garden where it's fine to relax security is a bad idea.
It is a bad idea, but it happens in practice. For instance, I can vouch for the security of my desktop (except for the times I run some random development stuff bound to 0.0.0.0, for convenient multi-machine access). I can't vouch for the security of my printer, or my IoT bridge. As long as it stays true, someone breaching a single device on your LAN is already creating extra security risk for your other devices.
My Desktop/Laptop is supposed to be secured, and patched. Otherwise open wifi access points would be a bad idea.
Personally I think the the idea that the LAN is some walled garden where it's fine to relax security is a bad idea.