I want a narrow right-to-repair rule for cloud-dependent hardware: when a manufacturer ends service, it should provide a documented “sunset package.” That package would include signed, version-pinned firmware, recovery and service documentation, an authenticated local administrator path, encrypted user-exportable backups, and a tested procedure for moving credentials and settings to a replacement controller.
That does not mean handing out unrestricted root access. Secure boot, owner authentication, signed updates, audit logs, an explicit factory reset, and revocation of the old controller’s keys could preserve a meaningful security boundary. Cloud analytics, remote access, and hosted storage can remain subscriptions; local setup, physical operation, recovery, and migration are closer to ownership.
Would this be a reasonable right-to-repair requirement, or an unacceptable security liability? I’d especially like examples from smart-home, robotics, or maker hardware.