> I think all software should be as secure as it's feasible to make it. But I don't think that security should ever operate against the person who bought the device and is sitting in front of it.
I don't think that software, in general, should place the interests of the software author above the interests of the user.¹ I just don't think that's specific to TLS or DoH; it's a general problem of running software that doesn't operate in your best interests. And I feel like laying the blame for that on TLS or DoH, rather than on the software author working against the user's interests, has the net result of making it harder to make software more secure, because it contributes to pushback against those technologies in general.
¹ Modulo some reasonable caveats and subtleties like following standards, which place one interest of the user above another interest of the user.
I think TLS and DoH are net wins in the world, due to all the positive benefits they have, despite the fact that they (like many many other technologies) are also sometimes used for anti-user purposes.
And, of course, if you control a device that includes controlling the software running on the device, which includes arbitrarily debugging, intercepting, or modifying it. I'm glad to see people who legitimately control a device using whatever technologies they desire to prevent software from working against their interests. (Though I continue to believe the right solution there is to not run software that runs against your interests in the first place, whenever possible.)
Well fortunately for user choice there are people like me who are going to build and distribute software that is not prescriptive about what certificate authorities users should be compelled to accept as net wins as well as people like you who apparently are willing to navigate a twisty rhetorical maze before arriving back at: status quo, intact.
my intention is to render your net win calculation irrelevant by letting users decide and educating them about the implications of trusting people like you.