Cops hate encryption but the NSA loves it when you use PGP
theregister.co.uk
theregister.co.uk
1. configure your browser to use a separate CA store from the OS one;
2. set up a VPN tunnel to a jumping-off-point not within your ISP's reach;
3. hide that tunnel's traffic steganographically within a regular "encrypted but actually MITMed" connection to your VPN server.
These three steps could even be put together into a little middlebox to put between your home router and the Internet, so each device could keep its OS-level CA store sane, while still appearing to the ISP that everything is regular MITM-able traffic.
My take: If someone has something to hide, they're likely to encrypt their communications. Encrypting their communications alerts the NSA that this person has something to hide.
Which is why you should practice good opsec and always encrypt everything, even when you're not doing something that "needs to be hidden".