https://www.digicert.com/blog/https-only-features-in-browser...
https://www.chromium.org/Home/chromium-security/deprecating-...
https://blog.mozilla.org/security/2018/01/15/secure-contexts...
Look at the trend. First it was just a small SEO bump.
But so often the device doesn't have any name at all, so it's maybe 10.0.0.1, and so is everything else, the problem only appears to be in the security layer because that's the first place which absolutely insists that you can't have a situation where everybody is just named "Bruce" with no other identifier.
Where it does have a name, the name is often not part of the global namespace. At least here we can fix that with a namespace suffix. Sold five million routers with serial numbers? Name them $serialnumber.routers.your-company.example and problem solved. Now that they have a name, issuing them certificates isn't difficult.
(Yes, a commercial vendor who'll hook you up with five million certificates won't do it for free. The little rubber feet and the half-arsed English translation of the instruction manual weren't free either. Too bad)
As a user, I don’t want local networks setting me up to make me recognize their CA services.
At first I liked SSL everywhere, but now I’m seeing a lot of hacks that are going to make SSL less useful.
You say that as if users don't already mindlessly dismiss most warnings already. I'm not convinced this would be that big of a difference from the current system.
The thing issuing DHCP leases has full control over your ability to connect to the internet anyways, so around here seems like the right place to put it.
My only qualm is that I trust router manufacturers to implement this correctly about as far as I can throw a sheet of paper.
If this trend continues it means you will no longer be able to configure these devices with a webbrowser but forced to use the manufacturers "cloud solution" or install an app where both ends of the TLS connection can be controlled and you're not bound to public CAs.
It’s not a good trend, but this is a plus for most consumers who don’t care about local network security.