- There is no non-free firmware or other software on the device.
- The consumer is provided full source code to the software and can effectively replace the preinstalled version with a version they have compiled themselves.
- The manufacturer provides updated versions of any software or firmware (again, including full source code) to patch any discovered security vulnerability for the expected life of the device: at least three years for most devices, but perhaps as long as 30 to 60 years for some devices. This lifetime is disclosed.
- The device does not transmit any personally identifiable information back to the manufacturer in its default configuration; for example, audio recordings, power usage measurements, accelerometer readings, temperature readings, or customer login names or account numbers.
Unfortunately, I don't think such requirements are viable in the current political situation. That doesn't change the fact that any device that fails to comply with them introduces a serious security vulnerability: there is no way for the users to defend themselves against malicious actors who penetrate the manufacturer. The Dieselgate scandal and the Huawei prohibition are only the mildest taste of what we are in for.
Of course it is not practical for every person to audit the source code of the firmware for every TV remote control and power brick they use, but it is possible for people to organize consumer watchdog agencies that do perform such audits.