pull down to refresh

Why even on your network? What about it gives you this level of concern?
MoneyPrinterGoBrrr is changed by any sane user after first login. 2FA is available, so no, stealing raspi won't be enough. But yes, a hacker guest with wifi password can sniff traffic with wireshark and maybe get the real password (I could not, must be hashed).
Most people never change the default.
Why blame Umbrel for this? If I remember correctly, Umbrel 1.1 forces you to change the password on first login.
No, not all default passwords.
I talk about the main password MoneyPrinterGoBrrr. The internal passwords of some apps are redundand.