I don't think they've implemented certificate validation since I've left though.
My naive hope, going on many years, is that SCRAM with channel binding would have landed years ago (the first versions of the patch began to show up then), making client-side certificate checking (and let's get real: it's hard enough to use that many people will not validate when developing from their laptops, simply backspacing out the optional cert validation connection option, a elision that is invisible to the server) obsolete. It should be possible to modify the definitions of pg_hba.conf to require a channel-bound SCRAM connection, which would mean that the client is certain to have checked for an untampered certificate.
This implementation of SCRAM doesn't have that yet, but it's been an ambition of the author for some time to do so.
So yes they're public but their addresses are basically impossible to guess.
[0] https://en.wikipedia.org/wiki/Security_through_obscurity
It's still not good practice, since most systems treat addresses with far less care than passwords and often save and/or transmit them unencrypted.
I still think it's a low-friction solution. But a secure one -- hardly.
Ipv6 only then?