The mechanism and the record

Firmware updates arrive over the air, applied automatically by default on most connected hardware, and they do not always add capabilities. They remove them. A software patch has disabled third-party accessory support in printers, narrowed the tuner range on networked radios, and, in documented cases, bricked devices entirely ↗ — leaving working hardware inoperable with no published rollback path.

The printer case is the clearest pattern. HP's firmware updates, deployed across multiple product generations, blocked third-party ink cartridges from functioning in devices that had accepted them the day before. iFixit and consumer-rights groups tracked several of these pushes; the European Commission has noted printer consumables lock-in as a right-to-repair concern in its ongoing product durability work. The hardware was physically unchanged. The update redrew the contract.

Smart-home equipment follows the same logic. Revolv sold a hub on the premise of local and cloud-connected control; after Nest acquired the company, a 2016 server shutdown made the device permanently non-functional. The firmware was never updated to allow independent operation — the absence of an update was itself the ending. That case is close enough to an intentional brick that the Revolv shutdown stands as the reference point for what a cloud dependency can cost.

Chronology

  1. 2016Revolv hub permanently disabled after Nest shut down its servers
  2. 2020Sonos "Recycle Mode" incident; irreversible wipe triggered ahead of trade-in program
  3. OngoingHP firmware updates blocking third-party cartridges across multiple product generations

Sonos issued a 2020 "Recycle Mode" that wiped devices before a trade-in program; the mode was irreversible, and the permanent disabling of devices that could otherwise have been reused drew widespread criticism.

Audio hardware offers subtler examples. Sonos issued a 2020 "Recycle Mode" that wiped devices before a trade-in program; the mode was irreversible, and the permanent disabling of devices that could otherwise have been reused drew widespread criticism. Separately, the same cycle applies to security cameras, robot vacuums and connected locks when a vendor discontinues a product line and stops signing older firmware against its own authentication servers — the device can no longer validate its own software and refuses to boot.

The mechanism that makes this possible is the same one that delivers security patches: an always-on authenticated channel to the vendor, with the device configured to trust and apply what arrives. That trust runs one way. The Connectivity Standards Alliance ↗ has worked toward local-fallback provisions in the Matter standard, and projects like Home Assistant exist precisely to route around vendor channels, but neither addresses devices that check authenticity against a server before running at all.

Residual value after a damaging update is effectively zero. You cannot sell a device that has been functionally reduced, and you cannot restore it. What you own is determined not by the hardware you paid for but by the last firmware the vendor chose to push.

Small round smart speaker with gray fabric top and white base on a table
A shelf of identical dark plastic units, one raking light
Devices that stopped working on purpose — The server went off; the hardware was fine.Photo: mali maeder / Pexels