[1] http://ul.com/
> We need the Antivirus-TÜV now!
I can imagine, in future, that an OS becomes like a nation. There's a core, transparent "government" component of the system which takes care of all low-level resource managements and security (just like a real life government) and there's a proprietary app which has a secret component but has to play by rule (just like a real private company). All the government behaviors and its legislators (i.e. maintainers) are constantly monitored by its users and media, and they are accountable for their actions.
Yes, this is far from perfect, and while we still might have the NSA of a kernel and the Enron of 3rd party apps (whatever it means), I'd argue this is better than the current everything-is-proprietary model.
There are botnets in the millions running on supposedly "Norton-protected" PCs.
No one cares. It's not a problem the people in a position to do anything about even understand.
Having your server hacked is one thing. Making kitchen appliances burst into flames - which is not impossible with remote control - is something else entirely.
It's a national security issue. Imagine a state actor or a terrorist org deliberately launching a synchronised mass IoT attack against another country.
Imagine the attack is untraceable because it's routed through all the botnets out there.
It's great the NSA wants backdoors everywhere, because that will make attacks easier to trace - wont't it?
We'll want to document the successes and failures of security software companies, their auditors, and their auditors.