You lose functionality though, like being able to check doors etc. remotely.
I trust Apple and I trust Homekit so I'm not too concerned with that.
You don't. That's what VPNs are for.
If it's an end-to-end VPN, it's doubtful most of these devices have the power to run a client.
And god help us when all these IoT devices start talking IPv6... With no NAT and anemic firewalls on most routers? Oof.
But John Doe does not care, he wants convenience to the point where the IoT manufacturer knows everything about how they use the product.
Assign Unique Locals ( ULA ) to untrusted LAN devices and no Internet router will carry them.
Then your laptop or phone can additionally receive a routed prefix. Remember with IPv6 you can assign an arbitrary number of prefixes and addresses to each interface, or just one. It makes for very flexible routing.
IDIoT
Do the security right and the classic internet of shit botnet type vulnerabilities aren't really an issue (knock on wood...)
Anyway, we've managed to survive pitching internet connectivity instead of local network, and several customers have found use cases for it that I don't think local would be feasible for.
In the end it's not just "technically a LAN would be the most secure option here," I mean that's always the case. It can be more "our partners and solution are offering a so-far-unbroken security model, and connecting via the Internet makes the whole manufacturing, distribution, on-site enrolling, and monitoring cheaper and working out of the box."