Just curious, what is your tech stack to life inspect all TLS traffic?
The method used by the individual on their home network is no different than the the method used by the Fortune500 and NASDAQ100 on their own networks
A variety of software can be used
Anything from something like socat up to a large proxy server will work
I read NYT with no cookies, no Javascript and no images. Only the Host, User Agent (googlebot) and Connection headers are sent. TLS forward proxy sends requests over internet, not browser. No SNI. No meaningful "fingerprint" for advertising
This only requires accessing a single IP address used by NYT. No "vendors"
TLS is monitored on the network I own. By me
I inspect all TLS traffic. Otherwise connection fails