Correct me if I am wrong but I think we still should be able to create a self sign certificate and let Pi access all the traffic so that it can block the unwanted one.
Not if the app and or website use certificate pinning or hsts and you want to use the device on a different network as well, e.g. phones and laptops.
HSTS would need to be disabled in all browsers for all clients to allow for mitm proxy. I’ve seen it done in corporate environments.
So in order to prevent seeing ads we are opening ourselves up to other vulnerabilities. This might be a choice some tech minded people can make but is definitely not something for the masses.
I don't think a website can decide to use public key pinning can it? But the client/browser can. Google won't let you route their traffic through a proxy (chrome does public key pinning for Google).
Websites can but apparently Chrome and Firefox ignore incorrect certs when the presented cert is from a user installed CA [1]. I guess this is to allow firewalls to MITM the traffic.