Physical devices already do this: https://mailarchive.ietf.org/arch/msg/dnsop/WCVv57IizUSjNb2R...
At least a browser might have a user setting to disable it.
At least a browser might have a user setting to disable it.
Keep in mind you're on HN-- we tend to be a more technical population :). If you're interested I found this on StackOverflow via Google: https://unix.stackexchange.com/questions/144482/iptables-to-...
You'll have to Google how to set up iptables/telnet or ssh on your router yourself, assuming it supports it.
The next game will probably be mitming these devices by flashing a new CA store.
There is no general solution to running an openly adversarial app/device in your network.