Tech & Sourcing @ Morgan Lewis


The Federal Trade Commission (FTC) recently warned that Internet of Things (IoT) products and services that are no longer operational, updated, or supported present significant issues related to consumer expectations, security, and privacy. Although the FTC noted the industry’s bright future within a product sunset context, the implied “parade of horribles” could have been framed in the grim style of poet Archibald MacLeish as an “ever climbing shadow.”

Internet-connected devices that cease functioning properly, or as expected, could lead to problems on several levels. For example, some IoT devices and services will be serving safety and other important roles, and malfunctions could lead to injury, property damage, and theft, especially if consumers are unaware of product limitations. Second, out-of-date IoT products are more likely to be vulnerable to hackers and bugs. Finally, because IoT products will be tangled in a web of connections, security failures in one device could spill over to other devices and “put consumers’ sensitive data at risk.”

The FTC encouraged IoT businesses to think through product sunset issues ahead of time and to clearly communicate to consumers what to expect regarding IoT products, such as

  • a device’s nature and function,
  • how long a product will be functional or otherwise usable,
  • the risks of using a product past its life expectancy,
  • how and when a product will be updated, and
  • the extent and duration for which a product’s security will be maintained.

Although seemingly brilliant, the future of the IoT revolution may depend on whether the industry comprehensively addresses product weaknesses and end-of-life strategy, taking heed of “how swift how secretly the shadow of the night comes on...”