Yeah, the parent comment is not accurate. IP spoofing is only possible if you control the entire L4 stack.
If an attacker can do it, you must assume they will do it. Because they will. That should be the starting point for any threat model.
"the attacker probably won't read my password through the wall from the radiation off my keyboard"
if your starting point is APT-level adversary then you might as well give up
Lets face it, for most businesses and pretty much all home users* the best they can hope to achieve is not to get owned by various automated attacks.
If some determined attacker is trying to get in, he will get in.
* Sure there are exceptions