You can't have your cake and eat it too.
If you want to buy an off-the-shelf "home appliance" you will get just that -- a product where you cannot update firmware/software, reconfigure security and firewall settings, etc. Maybe it's secure the day you buy it -- but in 5 years? With no updates? No way.
If you buy something more enterprise grade -- or, the best option, roll your own with some of the very good options like FreeNAS or OwnCloud, then you will be able to keep it secure and up-to-date. But this takes more effort - and is likely the reason the OP did not opt for one of these very fine options.
> "It's a worrying meme that you shouldn't even expect your internet-connectible devices to survive the internet, and when they break its your fault."
That's not true -- you have an ethernet/network capable device; not an internet capable device -- nowhere on the box does it say "Plug this directly into the open public network in front of your firewall or inside a DMZ. You need to be responsible with your devices. Just because it can serve a web page does not mean it should be accessible over the internet! This is true even with enterprise grade gear.
Saying you want to not worry about security at all but still want to put devices on the public internet that need protection is like saying you want to have a car but don't want to ever change it's oil. Sure, you as an individual can avoid changing oil -- hire a technician. Same goes with your home network.
So no, it's not a bad attitude -- it's irresponsible and/or ignorant home users.