If the vendor can't even secure their update server; how long do you think it would be until some RCE on these 100k un-patchable routers gets exploited?
The only people to blame for this is the vendor, and they failed on multiple levels here. It's not hard to sign a firmware, or even just fetch checksums from a different site than you serve the files from...
the fallout is some companies losing their revenue: https://status.neoprotect.net/ and other headaches for people all over the world
relevant law here: EU Cyber Resilience Act (CRA).
Fine, but that is the real discussion to have. Not 'it has this risk and therefore is bad'.
> banning vendors that do not secure their devices
I think the goal is to encourage positive behavior, not try to monitor everyone and evaluate their updates.
> promotes them to include sloppy (insecure) implementations for pushing said updates just to do bare minimum to comply with the law
I imagine the law is more than just one clause ?
And the other option isn't that much better, because "don't do autoupdates because maybe the update server is compromised" leads to a bunch of unsecured devices everywhere.
The only "real" solution is also completely unrealistic: Every private person disables auto updates, then reads the change log, downloads updates manually, and checks them against some checksum.
The better solution would be to simply increase fines until morale improves.
While it doesn't make it mandatory, it does require patching devices in a timely fasion which in other terms: requires forced updates - pushing updated firmware is not enough if you read between the lines.
Even stronger requirements come into effect at the end of 2027.