You can easily still secure an EOL device- with the old Mac I just use it with the firewall on, no ports open, and a modern secure browser. There is really no attack surface from the OS which is EOL, and this old device has aged past being worth developing attacks for.
So
* manufactures open source it
* "someone" is going to maintain it, for free
* all these people are going to find non-malware infested fork
* upload custom ROM to their devices.
I just don't see it.
Automatic updates/killswitch are the only way forward.
An EOL device that has withstood the test of time, and has had many security patches but is no longer connected if often one of the most secure devices.
for those that can secure them properly (e,g air-gapping) why do we need to make old iot stuff non-functional bricks?
something I'd be more ok with is to disable it, but in the device's settings, allow it to be re-enabled