it's fair to say they do and have for ages... it's not that hard to assume a well trusted TLS cert is under their control.
Having a magical cert doesn't mean you can just intercept everything.
No mainstream browser (or any browser?) is doing cert pinning.
What "other methods" are there that are deployed and actually in use?