Mobile app security standard for IoT, VPNs proposed by group backed by Big Tech

I don't suppose there's any requirement that the mobile app be allowed to control the IoT device without the vendor's server mediating it.

