The internet setup wizard is a pain to even get to these days esp if you are trying to run it on a “dirty” device that has already been used online and is enforcing HSTS.
You can only redirect them to the wizard if they try and connect to a non https site or the non http site of a https site they have yet to visit.
Same mother. She has a 4g sim in her iPad cheapest deal for her usage level is prepaid sims. When the prepaid credit is gone it’s cheaper to use an new sim than top up the exisiting sim. Except you have to go though a activation portal to enable the sim. It’s easy. Pop in the new sim, visit telcos website or any non https valid domain press the active button and away you go.
She still can’t do it. And in a world where more and more people are using apps instead of browsers where preinstalled apps will just fail you are gonna not to cause even more issues.
BTs Smart Setup captive portal on their routers was one of the most annoying things they did. And when searching for it the top results are for turning the thing off. Why? Because it interferes with devices that can not display the portal, Smart TVs, Amazon TV sticks, Settop boxes, webcams, IoT toasters, etc.
While they haven’t removed it from their latest router they have had to make disabling it much easier than in previous versions.
With the number of end user devices on the market, I just don’t see them managing to pull it off by getting end users to install their cert.
But you touch on a point. You say that Chrome would have to just suck it up from Comcast. Now I’m not saying I disagree, but why would Comcast go though all that pain to get end users to install a root ca if they held so much power over Chrome (the largest browser my customers use) then why not just get the browser to install the cert anyway and save all that hassle with your end users. Think of the savings they would make not having to handle all those support calls.
Like I said. Possible? sure, practical today? I don’t believe so.