In this case, we might say that the manufacturer has a much stronger responsibility to keep their devices under control than in the case of, say, a typical PC where the user assumes more of that responsibility. The less freedom you give your users, the more power you reserve for yourself. That power should come with corresponding responsibilities.
For example:
- Mandatory security auditing of all pre-installed software
- Mandatory security updates for X years
- Mandatory insurance for damages caused by vulnerabilities in your products
Allow some of these requirements to be met by reusing previously audited and/or independently maintained software, giving manufacturers an incentive to stick with well-tested standard components. Waive some or all of the requirements if the device is allowed to be used as a general-purpose computer and/or all the software is freely available.
Best case scenario: we get routers and TVs labeled "Red Hat Embedded Linux inside: security updates guaranteed for 10 years."
As long as the industry is allowed to come to these SLA-like stamps on their own, on a per product basis, without government regulation breathing down their neck, this is exactly the way to go. IoT is so wide, there is no such thing as a "one size fits all". Any talk about across the board rules stinks of missing this obvious reality.
Nowadays, it's cheaper to stick a generic ARM SoC in your product and install a LAMP stack on it. It's also easier to find cheap developers that way. My router is just a bunch of CGI scripts running on an outdated Linux distro.