But this is a decision you in effect made, those devices needn't even use TLS, they could use Jim Bob's secret MITM-defeating crypto thing and you can't "hack" that either, you bought devices that are resistant to being reverse engineered.
Governments could legislate of course, there could be a rule that means you can't sell Nest because it doesn't have some "hack" feature. After all the EU mandated people provide a sane charge port on phones and it more or less worked, even if you don't live in the EU your phone likely no longer has some arbitrary custom charge port on it, and you can buy replacement chargers or keep the one from a previous phone, reducing waste.
You also could legislate from the far end, for public services, you could say if I own a device using my credentials to do stuff, I get to have the agreed key material so that I can decrypt messages after the fact. That's a huge pain to implement, most of the ways to do it make everybody's security a bit worse, but it isn't technically impossible.
But technologically we can't change the mathematics of the encryption, Diffie-Hellman works, two parties can agree a secret (which in effect becomes a symmetric key) without either of them uttering the secret.