The question that Google seemed to ignore (and still does) is "how do you expect a newly unboxed network device to ship with a non-self-signed SSL certificate?" The workaround some manufacturers have come up with is more repulsive than the original (There was one Chinese manufacturer that tried to get a signed certificate for a domain, then mapped that domain to 192.168.0.1 and shipped the private ssl cert w/ every router iirc. TP-Link has their own weird workaround where they give you a domain to log in to the router instead of the IP, and their router MITMs the connection and redirects to HTTP.)
Google forcing everyone to HTTPS is one thing, Google forcing everyone to HTTPs and universally treating self-signed HTTPS connections as scams is another.
[0]: https://neosmart.net/blog/lets-stop-punishing-iot-devices-th...