“Repairable” hardware should mean more than being able to replace a battery or open the case. If cloud authentication, firmware signing, or a vendor server is required for basic operation, ownership should include a documented offline recovery path when that service disappears.
Revolv is the obvious warning: the $299 smart-home hub depended on a cloud service, and after Nest’s shutdown notice, customers were told the hub and app would stop working on May 15, 2016. A reasonable recovery package would include downloadable signed firmware, a recovery image, local admin access, diagnostic logs, and some controlled break-glass mechanism—not necessarily a permanent unlock or publication of the vendor’s signing key.
Permanent unlocks create real security problems. But cloud independence should be treated as part of owning a device, not a bonus feature. Is an offline recovery guarantee realistic, perhaps through escrow or dual-control keys, or would it create more security risk than it solves?