No matter which attacker we want protection against, the points to secure are client and server, not the middle-boxes.
This is one of the well known reasons HTTP/2 is implemented by browser vendors only on a secure channel.
Here we are talking about implementing security in hardware (bad idea: hard to upgrade as security requirements and practices chage) at a very low level (at data link layer). If this is to skip security at higher levels of the stack, you have to trust all hardware vendors and operators worldwide. If we don't, we can as well communicate on an insecure channel: that's what modern TLS provides.
Of course to get all users to use only secure channels is a lot of work, it's just that there is no easier alternative that provides this same result.
Granted, the author might have something else in mind: he might want communication to be safe only against some parties, but not others.