Earlier quoted context omitted.
Solution #3: don't give any IOT stuff access to the internet, you don't want your adversary [1] to be able to access their spy agents nor to bring down the grid by rapidly switching on and off all devices under their control. The suggestion to use a VLAN is good but not sufficient, that VLAN should not have access to the internet. Any interaction with IoT stuff should be mediated by software under your control, trans…
This is not very realistic. Just don’t buy iot stuff at that point.
In other words this is quite doable for those who have some experience in setting up networked equipment. It is not something you'll tell your grandma to do but there is nothing keeping you from setting it up for her since it is a one-time job. It is also more than worth it for the gains in privacy, the reduction in exposure to exploits and the absence of the risks of automatic updates which take away functionality you depend on.