How tech companies turned physical ownership into a temporary software lease.
I. The Thing That Still Works
On the morning of April 9, 2024, Dropcam home security cameras mounted above front doors and living-room baseboards quietly stopped functioning. Google had officially ended cloud support the day before.
Mechanically, nothing was wrong with them. Their glass lenses were clean, their image sensors captured light without distortion, and their power adapters still delivered electricity. But inside the mobile application, every video window was replaced by a static notice: the hardware could no longer connect to the service.
Google had retired cloud support for Dropcam and Dropcam Pro. As documented in the Google Help Support Notice for Dropcam, the cameras lost all ability to stream video, record events, send security alerts, or adjust settings. The units had always relied on cloud infrastructure for streaming, storage, and motion-event processing, an architecture Dropcam’s own engineering team described in contemporaneous coverage of its Amazon Web Services infrastructure; once that infrastructure stopped serving the devices, the decision turned functional electronics into inert wall decorations.
The cameras were not broken. They had simply outlived the service that gave them purpose.
The episode illustrates a central risk of modern consumer goods: connected hardware has created a new kind of ownership exposure. Consumers can own the physical object while another company controls the software, cloud services, authentication systems, or repair tools necessary for its functions. When those external dependencies disappear, the hardware can outlive the product the consumer thought they bought.
II. The Product Behind the Product
When someone purchases an ordinary mechanical tool, such as an acoustic guitar or a manual hand drill, the boundary of the product is obvious. The item contains everything required to fulfill its purpose. Its utility is governed by material integrity, physical wear, and regular maintenance.
Connected products do not work this way. A smart doorbell camera, for example, touches six distinct operational layers before it ever displays a visitor’s face on a homeowner’s phone:
- Physical Hardware: The structural chassis, optics, microphone, and power circuitry.
- Embedded Firmware: Low-level software stored on local microchips governing hardware behavior.
- Client Applications: The mobile operating system interface required for control.
- Authentication Systems: Identity registries that verify user accounts and validate access permissions.
- Cloud Infrastructure and APIs: Remote server networks handling off-device computation, telemetry, and storage.
- Third-Party Gateways: External cellular networks, push-notification services, and mobile operating system channels.
For connected products, the appliance is no longer an isolated product. It is a dependent terminal whose ongoing utility relies on external systems maintaining continuous cooperation. The buyer has the strongest direct control over the first of these layers: the physical hardware itself. The manufacturer typically controls the firmware, client software, authentication, and cloud infrastructure, though the entire system still depends on external operating systems and network carriers it does not control.
III. The Economics of Ongoing Support
Why do companies discontinue services for hardware that still works?
In most traditional manufacturing sectors, the primary transaction between buyer and seller largely concludes at retail. A company designs an appliance, covers manufacturing and distribution costs, reserves funds for statutory warranty claims, and takes its margin. If a consumer uses a refrigerator for fifteen years, the manufacturer generally does not have to keep a server, database, mobile application, or authentication system running for that individual appliance. Traditional manufacturers certainly manage long-term costs, including replacement parts inventories, recall campaigns, and customer service networks, but the physical product does not require an active digital pipeline to perform its primary job.
Connected hardware breaks this financial logic. The moment an internet-enabled device is powered on, it begins generating continuing expenses that many traditional products did not impose on their manufacturers: cloud hosting, database maintenance, mobile application compatibility updates across new phone operating systems, and ongoing cybersecurity patching. Maintaining secure server infrastructure, database instances, and backward-compatible firmware pipelines requires dedicated engineering teams, and these operational costs can persist even after the hardware stops generating fresh retail revenue.
As sales of a legacy device decline, the pool of active users typically shrinks, but infrastructure and maintenance overhead may not fall in direct proportion to the shrinking base. Companies may retire services when the cost and complexity of maintaining legacy infrastructure no longer appear commercially justified. Over time, aging hardware can transition from a past commercial success into an indefinite support burden.
IV. The Graveyard of Working Hardware
The smart-home sector provides documented examples of how this operational tension plays out in practice:
- Revolv (2016): The smart-home hub had promised lifetime connectivity across multiple home-automation radios. In 2014, Google’s Nest division acquired the startup. Less than two years later, the service was shut down. As contemporaneous reporting in The Guardian on Disabled Revolv Hubs documented, both the mobile application and the physical hub ceased operating simultaneously on May 15, 2016. The decision drew sharp criticism from affected owners and the technology press, highlighting how easily functioning hardware could be disabled from afar.
- Dropcam and Dropcam Pro (2024): Google terminated cloud support on April 8, 2024, ending video streaming, recording, and app management for cameras that had entered the market more than a decade earlier.
- Nest Secure (2024): On the same day, Google ended cloud services for its Nest Secure alarm system. As outlined in the Google Help Nest Support Advisory, the associated Nest x Yale smart deadbolts did not become entirely useless: owners could still unlock them using physical keypads, and Google offered free Nest Connect bridge hardware to preserve Wi-Fi connectivity through alternative pathways. But the central Nest Guard hub was permanently retired from the Nest app, eliminating mobile arming and cellular backup.
- Belkin Wemo (2026): On January 31, 2026, Belkin discontinued cloud services and app support for selected legacy Wemo smart plugs and wall switches. As detailed in the Belkin Wemo Support Advisory, units that owners had previously integrated into Apple HomeKit continued to function locally over the local area network, while remote out-of-home control and automated cloud rules were terminated.
The Wemo case highlights a critical technical reality: architecture determines survival. Devices engineered to depend entirely on proprietary cloud servers lost their core utility; devices built with local protocol fallbacks could keep working without it.
V. When the Business Model Dies
The operational hazard deepens when the operating company itself falters.
Historically, a manufacturer’s financial collapse did not normally disable the physical products it had already sold. The machine outlived the firm.
With cloud-dependent hardware, corporate restructuring can jeopardize functionality, particularly when it results in discontinued cloud services.
The Humane Ai Pin provides a contemporary case study in this vulnerability. Marketed as a screenless, wearable AI communicator, the device was an extreme expression of the multi-layer model, relying on remote authentication, proprietary cloud infrastructure, and cellular carrier gateways for its primary functions.
When Humane wound down consumer sales of the hardware, its support documentation confirmed that as of February 28, 2025, the Ai Pin would disconnect from company servers. Basic offline indicators like battery status remained, but it could no longer call, message, sync data, or perform its cloud-dependent AI functions: the core capabilities that justified its original $700 price tag evaporated. The physical components survived, but the service that animated them did not.
VI. Four Ways Software Can Impair Hardware
Software control over physical products is not uniform. Full remote-bricking represents the most dramatic outcome, but software-driven obsolescence operates across a broader continuum of control:
| Category | Primary Mechanism | Practical Consequence | Real-World Precedent |
|---|---|---|---|
| 1. Service Shutdown | Decommissioning central cloud servers, APIs, or authentication endpoints. | The device loses access to the external infrastructure required for its primary function. | Humane Ai Pin; Revolv Smart Hub |
| 2. Feature Withdrawal | Terminating companion apps, cloud integrations, or mobile operating system compatibility. | The device reverts to basic manual operation; connected capabilities vanish. | Google Dropcam; Belkin Wemo cloud plugs |
| 3. Subscription Gating | Using software to condition the operation of physical components or consumables on recurring fees. | Physical features or supplies remain on-site, but software keeps them dormant or disables them until paid. | Connected vehicle options; subscription printer supplies (e.g. HP Instant Ink) |
| 4. Repair Authorization | Component serial-number verification and proprietary electronic diagnostic requirements. | Replacement parts may require software-based calibration, pairing, or fault-code procedures before the machine returns to full operation. | Manufacturer diagnostic locks; Deere agricultural machinery |
These mechanisms can overlap in practice. Subscription gating and repair restrictions may leave a path back to full functionality, but that path depends on the manufacturer’s continued cooperation, whether through payment, authorization, or diagnostic support, and in Deere’s case that cooperation had to be secured through regulatory intervention rather than volunteered. If the operating company dissolves, that path closes for good, leaving the hardware as stranded as any device severed from a cloud server.
VII. When Repair Requires Permission
The same divide between physical possession and digital control now reaches physical maintenance.
In traditional mechanical repair, restoring a machine depended on two variables: acquiring the correct physical part and completing the mechanical labor. [Item 14, interpreted:] In a purely mechanical system, correctly installing a functioning replacement part, such as a water pump or fuel injector, was generally sufficient to restore operation.
Modern machinery can add a third hurdle: software-based diagnosis, calibration, or component pairing. After an electronic component is replaced, the machine may require diagnostic procedures before the new part is recognized or the system returns to full operation.
Federal antitrust scrutiny eventually followed in the agricultural sector. On July 8, 2026, the Federal Trade Commission, alongside state attorneys general, announced a comprehensive settlement with Deere & Company. As detailed in the FTC Settlement Announcement with Deere & Company, the regulatory order specifically mandates that Deere provide farmers and independent repair providers with repair resources equivalent to those furnished to authorized dealers. Crucially, this includes the software tools necessary to read, clear, and reset electronic fault codes, as well as the technical capability to reprogram and pair replacement electronic components.
The settlement underscores a broader point: the practical ability to repair a machine is incomplete if proprietary software restrictions prevent it from recognizing or operating with a replacement component.
VIII. The Subscription Switch and Conditional Functionality
Manufacturers in several sectors increasingly use software to gate physical capabilities and consumables after the initial point of sale, installing common hardware across multiple configurations and activating features, or restricting supplies, on demand.
This practice divides into three commercial tiers:
- Ongoing Cloud Services: Subscriptions tied to external network bandwidth, such as live satellite navigation and in-car Wi-Fi.
- Software-Defined Performance: Subscriptions for computational algorithms, such as the Mercedes-Benz USA Performance Acceleration On-Demand Upgrade, which offers an annual subscription on EQE and EQS electric vehicles in North America to boost motor output via software tuning.
- Hardware and Consumable Gating: Subscriptions or post-sale software fees that condition access to physical hardware or built-in consumables already present in the product, such as a vehicle’s heated seats, a portion of an already-installed battery pack, or ink already loaded into a printer cartridge.
The third tier extends across both hardware and consumables. In automotive markets, when BMW launched a pilot program in selected countries charging a recurring monthly fee to activate factory-installed heated seats, consumer backlash was severe enough that the company retreated from the program in September 2023, as reported by Edmunds. Concurrently, as documented by Electrek: Tesla Starts Selling Software Range Unlocks for Model Y RWD, Tesla produced Model Y variants equipped with battery packs capable of additional driving range, later offering software unlocks for an added fee. In consumer printing, programs such as HP Instant Ink Account Subscription Terms supply cartridges that stop functioning at the end of the final billing cycle once an account is canceled, even if the cartridge remains full of physical ink.
Post-sale feature unlocking does not overturn property law: in an outright purchase, the consumer still holds legal title to the vehicle or printer. However, it alters the economic relationship between ownership and functionality. When an owner must pay recurring fees, or maintain an active subscription, to use physical components or consumables already inside their property, hardware ownership becomes economically conditional.
IX. The Security Paradox
A balanced assessment must recognize the genuine operational and security obligations manufacturers face.
Unlike traditional passive tools, internet-connected devices operate in an adversarial digital environment. An unmaintained, unpatched smart appliance is not merely an inconvenience; it can become an active cybersecurity hazard. This is not a hypothetical risk: in October 2016, the Mirai botnet compromised hundreds of thousands of consumer devices, chiefly IP cameras, DVRs, and home routers left on factory-default passwords, and used them to launch a distributed denial-of-service attack against Dyn, a DNS provider, temporarily knocking major sites including Twitter, Netflix, and Reddit offline, as reported by KrebsOnSecurity’s contemporaneous coverage of the attack.
Manufacturers face legitimate constraints:
- The Maintenance Burden: Securing connected products requires ongoing engineering labor: auditing codebases, backporting security patches to legacy hardware, and testing firmware against evolving vulnerabilities.
- Statutory Compliance Mandates: Under the European Union’s Cyber Resilience Act, whose requirements are being phased in through 2027, manufacturers face formal obligations to address and remediate exploitable vulnerabilities during a product’s required support period.
- The Transparency Gap: Despite this necessity, the FTC’s review found substantial gaps in disclosure: its examination of 184 smart products across retail websites found that 161, nearly 89% of those surveyed, failed to state how long software updates would be provided.
A structural dilemma emerges:
- If a manufacturer never updates software, the hardware remains exposed to network vulnerabilities.
- If a manufacturer maintains centralized update authority, it retains the technical capability to alter, restrict, or retire capabilities over the air.
- If a manufacturer abandons support, the consumer is left to choose between running an unpatched security risk on their home network or unplugging functional hardware.
The software conduit required to defend the consumer is also a mechanism through which the manufacturer can alter the machine’s capabilities.
X. The Six Layers of Control
To understand the legal reality of connected hardware, it is helpful to look past traditional notions of property.
Under U.S. copyright law, the first sale doctrine (17 U.S.C. § 109(a)) provides that the owner of a particular copy lawfully made is entitled, without the authority of the copyright owner, to sell or otherwise dispose of the possession of that copy. However, courts have long distinguished ownership of a material copy from ownership of the intellectual property embedded within it. The doctrine governs the disposition of particular copies; it does not confer a right to continued access to a manufacturer’s cloud service or ongoing software support.
To understand how ownership fragments in practice, it is helpful to regroup the six operational layers introduced earlier around questions of legal and practical control rather than system architecture:
| Layer | Primary Governing Question |
|---|---|
| 1. Physical Hardware | Who holds legal title to, and physical possession of, the machine? |
| 2. Embedded Software | What restrictive license terms govern the local firmware? |
| 3. Cloud Services | What external infrastructure is required for ordinary operation? |
| 4. Identity Accounts | What corporate account credentials are required to authorize access? |
| 5. Operational Data | Who can access, use, and transfer the data generated by the machine? |
| 6. Diagnostics | Who holds the software tools and authorization keys for repair? |
Where the consumer has purchased the hardware outright, the consumer holds legal title to the physical object. The remaining layers may instead be governed by software licenses, cloud service agreements, proprietary access controls, and applicable data and consumer-protection law. That gap between physical possession and practical control is one public policy has increasingly moved to address.
XI. Regulators Rewrite the Rules of the Machine
Regulatory approaches have begun to address these dependencies through different legal mechanisms. United States regulators have primarily relied on case-by-case antitrust and consumer-protection enforcement, exemplified by the FTC’s actions on repair restrictions. The European Union has instead enacted broad lifecycle rules for digital products, including the Cyber Resilience Act’s explicitly horizontal, cross-sectoral requirements:
- EU Directive (EU) 2019/771 (Sale of Goods): European law specifically defines “goods with digital elements.” Under the EUR-Lex Directive (EU) 2019/771 Framework, sellers must ensure consumers receive all necessary security and functionality updates for the period of time the buyer can reasonably expect, treating a failure to supply required updates as a lack of legal conformity under consumer sales contracts.
- EU Cyber Resilience Act (Regulation EU 2024/2847): Formally establishes horizontal cybersecurity requirements across connected products entering the European market. As summarized in the EUR-Lex Cyber Resilience Act Summary, phased in through 2027, the regulation generally requires a support period of at least five years, unless the product’s expected operational lifetime is shorter. Longer support periods may be required where the product is reasonably expected to be used for longer, and manufacturers must state this duration at the point of sale.
- European Data Act: Focuses on the data generated by connected products. As explained by the European Commission Data Act Overview, the regulation grants users of connected products, including products used by both owners and lessees, legal rights to access the data their machines generate and share that information with third-party service providers, including independent repair providers, subject to the regulation’s conditions.
The legal baseline is shifting. When an appliance requires ongoing digital support to function, the law is increasingly looking past the moment of sale to regulate the digital infrastructure that keeps the machine operable.
XII. Auditing the Connected Purchase
As long as regulatory frameworks remain uneven across global markets, buyers must evaluate the digital dependencies of hardware before purchasing. Each question below draws on the layers of control outlined above:
Questions for Buyers at Checkout:
- Offline Capability: Does the device perform its primary physical function if disconnected from the internet?
- Account Independence: Can you configure and operate the machine without registering an online corporate profile?
- Software Horizon: Does the manufacturer publicly commit to a specific date through which software updates and security patches will be maintained?
- Subscription Scope: Are all factory-installed physical components fully operational without an ongoing software fee?
- Secondary Transfer: Can the hardware be deregistered and resold to a second owner without proprietary re-licensing or activation requirements?
Structural Questions for Regulators and Manufacturers:
- Graceful Degradation: When cloud services are discontinued, does the hardware default to an open local standard (such as Matter) or a vendor’s own local-control mode (such as HomeKit) rather than becoming unusable?
- Repair Autonomy: Can independent technicians clear fault codes, calibrate replacement modules, and access diagnostic telemetry on fair and reasonable terms?
- Software Escrow: In the event of corporate insolvency, is the software, cryptographic material, and technical documentation needed to maintain the product deposited in escrow to permit community-led maintenance?
The more of these questions a product cannot answer, the more of its useful life remains dependent on the continuing cooperation of its manufacturer.
XIII. The Limits of Possession
Return to the darkened Dropcam on the wall.
Its glass optics are intact. Its power circuits deliver current. It remains an example of high-precision consumer manufacturing. Yet it cannot capture a single frame of video because an external server stopped listening.
For generations, the practical experience of ownership was closely tied to possession. If you owned the physical object, its future was yours to decide. You maintained it when it wore down, repaired it when it broke, and passed it on when you were finished with it.
Connected hardware has detached the physical object from that historical bargain. Durability is no longer solely a question of mechanical tolerances or careful stewardship; it is an ongoing negotiation with remote servers, software licenses, and corporate financial priorities.
When you purchase a connected machine today, the critical question is no longer simply how well it was built. The question is: how much of the future of the thing you bought is still controlled by you, and how much belongs to the layers you can never hold?
Primary Sources & Legal Authorities
- FTC Settlement Announcement with Deere & Company (July 8, 2026). Federal Trade Commission settlement and stipulated order requiring Deere to provide farmers and independent repair providers with repair resources equivalent to those available to authorized dealers, including specified software repair capabilities.
- FTC Staff Perspective: Smart Products Surveyed Fail to Disclose Software Update Lifespans (November 2024). Bureau of Consumer Protection market study evaluating 184 connected smart devices across retail platforms.
- KrebsOnSecurity: Hacked Cameras, DVRs Powered Today’s Massive Internet Outage (October 21, 2016). Contemporaneous reporting on the Mirai-botnet DDoS attack against Dyn, using compromised consumer IoT devices.
- SiliconAngle: AWS Keynote, Powering Up Dropcam Cloud, Metadata + More (November 2013). Contemporaneous industry reporting on Dropcam’s cloud-based streaming, storage, and event-processing architecture on Amazon Web Services.
- Google Help: Support for Dropcam and Dropcam Pro Ended. Official corporate termination advisory governing cloud streaming, video history, and app access.
- Google Help: Nest Secure Support Termination Notice. Policy documentation covering the phase-out of the Nest Guard base station and bridge solutions for connected deadbolts.
- Belkin Support: Wemo Support Ending Notice. Documentation of cloud service deactivations and local Apple HomeKit operational carve-outs.
- The Guardian: Nest Ponders Compensation for Owners of Disabled Revolv Hubs. Contemporaneous reporting documenting Alphabet and Nest’s decision to permanently shut down cloud support for the Revolv smart home hub.
- Mercedes-Benz USA Performance Acceleration On-Demand Upgrade. Corporate announcement detailing the annual subscription to unlock additional motor output on EQE and EQS electric vehicles.
- Electrek: Tesla Starts Selling Software Range Unlocks for Model Y RWD. Coverage of Tesla’s post-sale software upgrades to access dormant battery capacity.
- HP Instant Ink Account Subscription Terms. Official terms explaining how Instant Ink cartridges cease to function after the subscription ends and must be replaced with regular cartridges.
- Edmunds: BMW Heated Seat Subscription Discontinuation. Automotive market reporting on consumer response and the retirement of hardware-gated seat heating subscriptions.
- 17 U.S.C. § 109(a) – Limitations on exclusive rights: Effect of transfer of particular copy or phonorecord. Statutory codification of the first sale doctrine under United States copyright law.
- Directive (EU) 2019/771 on Contracts for the Sale of Goods – EUR-Lex. Legal framework governing digital conformity and required software updates for goods with digital elements.
- Cyber Resilience Act (Regulation EU 2024/2847) – EUR-Lex. European legislation mandating documented cybersecurity support periods for products with digital elements.
- European Commission: Data Act Factsheet & Overview. Framework governing access to data generated by connected products, including portability rights for owners and lessees and aftermarket repair access for independent providers.
