There are ~40 governments trusted to sign certificates by major operating systems.. For them, HTTPS is trivial to MitM unless you're pinning certs

Replies (3)

Won't the certificate headers still be visible to peeping toms?