> nobody should ever get used to the idea that their network is MITMing their traffic
and:
> surveillance technologies like this will be abused by people with power over others
Then simply do not add a CA or self-signed cert to your cert store. IOW: the default is secure against SSL MITM. Nothing to "get used to" or "abused".
> What happens when libraries and software starts dropping support for old, insecure protocols, and the new protocols are designed to treat MITM as an attack?
Much simpler than you think. In an Enterprise, they block what they cannot inspect. Clients do not own+run the networks, the enterprise does.
> What happens when they're spending huge amounts of money maintaining forks and patches?
This runs counter to your earlier argument: "You can block spam and outbound attacks without MITMing traffic."
How do you control a myriad of versions of client software on a myriad of versions of devices across a myriad number of applications? There are bound to be some software the Enterprise cannot control (e.g. proprietary, or simply does not have the resources to fix+recompile).