Most machines are in a home LAN behind a NAT router so unless the user explicitly port-fortwards or configures a VPN which results in the device having a secondary (external) IP address they are not exposed. Only a tiny percentage of our active userbase have devices exposed.
That's true, and in case of the LE the risk is obviously small. But those people often like to use a "simple" password where the risk isn't low. It's really need so much "effort" to use a propper password? But I think already was consumed too many time and space for this "why isn't accepted a weak password" thing.