Earlier quoted context omitted.
The implication here is that you can't trust the devices on your network. IMO that's itself a problem; rather than weakening encryption to enable network owners to analyze traffic on their network (which also harms dissidents who need secure network access), I would prefer a push for more trustworthy devices. The devices we own should be acting in our own best interest; we shouldn't need to treat them as adversaries.
> The implication here is that you can't trust the devices on your network. IMO that's itself a problem; A large part of trust is auditability. And a large part of auditing a device is looking at its communication. What we are kind of running into is the security implications of a debug-interface. Your point about dissidents needing secure access is a strong one. Any way to MitM a connection for audit purposes can be…
Sure, but you can also look at the device's communication if you have administrative access to it yourself, rather than trying to MITM it. I suppose this could be a vulnerability itself if done poorly, but users have administrative access to their PCs; why should other devices they own be any different?
>These are much more essential, so it is more important that it is hard to MitM them even if the user gives consent.
If the user gives consent, they should be allowed to inspect the connection. The device's UI can make it _very clear_ that they're about to do something dangerous, but it's their device and should be their choice.