Actually, yes they are. I'm not a big fan of legislation, but the upgrade crazyness has to stop at some point!
> For example, support for downgrades means you a security vulnerability can be reintroduced by a malicious user which may not be desirable
What if "I, the user" deem it "desirable"?
I'm holding to bios with known vulnerabilities so I can work around "security features" that are "for my own protection" like 1) preventing me from underclocking (to keep the security features of the now-dead SGX) 2) using any M2 WWAN or NVMe that I want
It's gone to a point where it's not desirable for me to upgrade, and to prefer the risks that come with an exploit as at least I know my freedom to use my hardware the way I want will not suddenly become limited.
Another example: getting root on android with mediatek was considered a "bug" and work a mandatory "upgrade" that prevent users from being able to get root that way.
But I want to be root!