"Please don't roll your own security" isn't much of an option when many of these things are running on custom stuff from the ground up. But, I doubt many will pay for a secure foundation to run on... Makes me wonder if the windows for IoT has any promise.
I guess my uninformed concern is… if I write an app that has an interface that manages a device that is suddenly embroiled in a class-action lawsuit, what are the chances that I'd be sucked into that lawsuit?