If your house plumbing is leaking there is water going out where it shouldn’t be.
Yes. Correct. Personally Identifiable Information openly exposed on the internet is information going out where it shouldn't be.
If your house is leaking, whether there's someone out there with a cup doesn't change whether your house is leaking or not. It only changes whether someone took your water ie. a breach
Data leak and data breach have specific definitions:
Data Leak vs Data Breach: What Is the Difference? While many use the terms "data leak" and "data breach" interchangeably, there is a difference between the two. A data leak often comes from within the organization either by accident or intent, while a data breach occurs when confidential or otherwise protected information is accessed, stolen, or used by outsiders without authorization. https://www.fortinet.com/resources/cyberglossary/data-leak
https://www.microsoft.com/en-us/security/business/security-101/what-is-a-data-leak
https://www.oaic.gov.au/privacy/your-privacy-rights/data-breaches/what-is-a-data-breach
https://www.ibm.com/think/topics/data-leakage
https://www.trendmicro.com/en/what-is/data-breach/data-leak.html
This is a data leak. We don't know yet if it's a data breach. We might not know until active exploitation.
Given the lack of control on this data, and that it wasn't fixed until the researchers told them about it, do you trust IDMerit to have the scrutiny on their logging to know if it was accessed externally? I don't.
I use LibreELEC on a mini-PC for my home TV. LibreELEC is a Linux distribution that runs Kodi and is pretty good for a media centre straight out of the box. I use a Rii Mini K25 remote (with a dongle) to control it: https://www.amazon.com.au/dp/B06XHF7DNQ
The downside is I can't control the TV itself with this, but this can be sorted out with a USB IR receiver (like this: https://amzn.asia/d/0hvzkP93), LIRC (https://lirc.org/) or something similar, *and a universal remote. On my to-do list lol
I have a DHCP reservation for the TV itself and it's blackholed on my network. The only reason it's connected at all is so I can monitor what it tries to do.
Edit: Also need a universal remote for the IR solution so it can talk to the PC IR receiver and the TV IR receiver separately.