From the independent-repair side, a device should have a vendor-independent local recovery path: downloadable firmware, diagnostics, and calibration tools that still work after an account system, subscription, or cloud service disappears.
Dropcam is the clean example. Google ended support on April 8, 2024, and the cameras could no longer connect to the Nest app, stream, record, send notifications, or change settings. That is cloud dependence, not inherently good security. Signed firmware and secure boot can prevent unauthorized code while still allowing a locally verified recovery package.
The boundary should be basic diagnostics, factory reset, firmware restoration, and qualified repair without a vendor server. An offline service mode could include warnings and restricted calibration steps. Should manufacturers be required to escrow versioned maintenance tools, or publish that service mode? Disagree, or share a device you have—or have not—successfully repaired offline.