But it is a retailer's responsibility to know what they are selling. If it was added after they started selling it and hidden in secret, sure a retailer might have an excuse. But it isn't really hidden, most often its put in their marketing materials as a benefit and have been knowingly doing it for many years now.

US retailers can be told they can't sell it here. If you buy it outside of that, well that is buyer beware, but 99% of people aren't buying things from Alibaba or ordering from some random foreign store, they are buying them off US Amazon, Walmart, big box retailers, etc. You don't have to ban things consumer level to deal with 99% of it, you just gotta tell big corporations no and stop dismissing any ideas that put responsibility or liability on big business.

The problem is that Amazon, Walmart & friends have said the "we are a platform, not a retailer" magic incantation, which means that through the power of friendship and unicorns they are now suddenly no longer responsible for the stuff they sell.

And the "retailer" on record is of course not a real company. They'll just pay some third-party to file a bunch of paperwork in Delaware, pay the $110 fee, and let it go bust if anyone tries to investigate it or make it liable.

>If it was added after they started selling it

While it's great we're getting the manufactures to just stop sending out straight malware and it should be stopped the next most obvious means of attack is just having the device update and add superaids to it's new functionality.

So, no, it won't stop 99% of it at all.

And honestly this isn't that much different from what US companies are already great at by providing updates that take away features we bought with the device.

And not just updating really doesn't save you, instead of being part of a factory botnet, you're just open to become part of some other botnet.