"Assuming a competent user" is absolutely not what IoT is about, it shouldn't be what most of our decisions as engineers should be about. I don't want to have to be a "competent user" for my fridge, lightbulbs, sex toys - i.e. everything is potentially going IoT.
Separately, no - attacks like CSRF will quite happily be routed and compromise an incompetently designed IoT device.