Here's an idea: set up a standard for devices not intended for unsecured direct internet connection so that they refuse to proceed if they detect they are on the open internet. That doesn't solve the ...