If they’re technically inclined enough to run an installer and log in to google/apple, then they can do it, or you can do it for them.
That said, your case is valid. I just dislike my services dangling out without proper security, unless they’re designed for it, and plex’s auth model rubs me the wrong way.
You’re using HTTPS, do you have child porn?