I agree with yedidya that fixing a ventilator or auditing security should be lawful; that justifies targeted exemptions. My objection is the word always. Reverse engineering is a method, not a purpose. If the act itself is always legal, then cloning a patented chip layout, extracting firmware from a payment terminal to defeat its locks, or copying a certified medical device becomes protected research until misuse is proven. We can allow repair, interoperability, and security testing without legal cover for copying or tampering. Legality should track purpose and harm, not the technique.