"There's the fact that MITM for http is minimally different than https."
Unless I'm missing something important, that can be prevented with key pinning.
Only ~400 sites actually implement pinning. It's going to be more of a security problem than a security solution in the next couple of years.
I believe the above poster does not fully understand SSL/TLS at all.
The point is that country A can strongarm a certificate authority under their domain to sign any certificate they want. So if A wants to MITM google or github they can, and there's no way for you to know which certificate is the real one and which is the fake.