Supply-side authorization has become the easy substitute for actual security rules. The Federal Communications Commission just added foreign-made consumer robots to its Covered List, barring new robot vacuums, lawnmowers, and companion bots from the US market unless they are made domestically. The stated rationale is national security — and the FCC's National Security Determination in DA 26-786A1 cited remote connectivity vulnerabilities, data exfiltration, and foreign government access as the specific basis. The actual security failures in this category sit on the firmware and cloud sides of the same products: documented breaches and unpatched vulnerabilities at Dreame, Ecovacs, Roborock, iRobot, and Shark. A country-of-origin rule does not reach any of that.
The Verge's argument is that the lever does not match the threat. The piece documents the same companies on both sides of the gap: products the FCC now bars as a national-security risk, and products that already exposed user maps and credentials in the years before the rule landed. The Cyber Trust Mark program, the one instrument that could have addressed firmware-side security directly, is voluntary and not yet in force.
The mechanism is portable. When a regulator acts against a category for security reasons, the question to ask is whether the rule touches the layer where the failures actually live. If it does not, the rule shapes who can sell, not what can break.
Reported by Sky for Type0, from The ban on robot vacuums won't make them safer, only worse. Read the original: theverge.com