Instead of Burp, I use Haproxy running in Termux. I have not run into any problems with HSTS.
The part about being able to see "what they're saying" is interesting. Assuming the people running "tech" companies wants users to trust them, the user's data/information being transferred to the "tech" company should be available to the user. After all, it is the user's network, it is the user's computer and it is the user's data/information, not the "tech" company's. It is also the the user's bandwidth. "Tech" companies do not pay the costs of transferring the data/information, users foot the bill.
A cautious user could decide that if the "tech" company will not share with her the deatils of the user's data/information being sent to the mothership, then she will just block the requests. In that case, installing NetGuard available from F-Droid will allow the user to list and optionally block DNS/HTTP requests. It falls short of instecting the contents of the requests, but it does allow the user to export lists of all DNS/HTTP requests. It can also export a list of all domains that the user allows to be resolved. This is useful for determining what domains apps need to access and creating whitelists.
Intentional "MITM" is obviously a common topic that gets discussed on HN from time to time. What bothers me about HN commenters on this topic is that they signal that they are familiar with what needs to be done, i.e., to MITM their own traffic, and want us to know they understand how one "could" do it, however it is unclear that they themselves are actually doing it. I sometimes wonder if this is tacit approval of TLS being used (strategically perhaps) to lock users out of monitoring their own computers and computer networks. Hopefully there are many HN readers who do monitor ther own traffic but are generally not commenting about it.
Governments could legislate of course, there could be a rule that means you can't sell Nest because it doesn't have some "hack" feature. After all the EU mandated people provide a sane charge port on phones and it more or less worked, even if you don't live in the EU your phone likely no longer has some arbitrary custom charge port on it, and you can buy replacement chargers or keep the one from a previous phone, reducing waste.
You also could legislate from the far end, for public services, you could say if I own a device using my credentials to do stuff, I get to have the agreed key material so that I can decrypt messages after the fact. That's a huge pain to implement, most of the ways to do it make everybody's security a bit worse, but it isn't technically impossible.
But technologically we can't change the mathematics of the encryption, Diffie-Hellman works, two parties can agree a secret (which in effect becomes a symmetric key) without either of them uttering the secret.
Sure, but devices that you don't have control over shouldn't be permitted to communicate anywhere at all ever.
> IoT devices sometime rely on sending sensitive data to their backends.
Such as literally anything.
> This data may include API keys, client authentication secrets and such.
Yeah that sounds like sensitive data alright. It's all data that the owner of the device should have but often do not because of misplaced corporate greed.
> By having access to that communication, you may be able to spoof identity of the IoT device from a PC or a hacked-device.
So what? If I own the device and it's on my network then I have every right to everything on the device.
> Not very desirable from IoT vendor point of view.
And that right there is exactly the problem. IoT vendors don't want to really give up ownership of something they've sold.
The average user doesn't know to care. They keep buying this garbage and, in turn, financing the lobby against consumer protection laws for embedded devices.
It makes me want to give up on technology and go live in a shack in the woods.