>in the same way most HTTPS errors are not MitM attacks but misconfigurations.
It's interesting that you make this comparison. For a while now I've been of the position that web browsers should scrap all TLS user interface stuff (padlocks, green bars, invalid cert warnings, self signed cert warnings etc), because it doesn't communicate any information that the average user can make any use of.
It's only one aspect of what makes a site 'secure' for users, and probably one of the far less important ones. The vast majority of attacks on users (info being stolen, malware being served etc) come from the site itself being compromised, not from MitM attacks by their ISP. The vast majority of warnings about bad certs are due to somebody forgetting to update it or config issues, not because of real MitM attacks. The vast majority of people just click through cert warnings. The padlock icon in the browser doesn't even do the one thing it promises since it's no guarantee that TLS is being applied all the way to the actual web server. XSS is a bigger threat to the average user but browsers don't warn about sites that aren't using CSP.
My theory is that browser devs always knew the padlock icon was bullshit snake oil, but they implemented it at the demand of the e-commerce industry. At the time it was difficult to get people to trust the web enough to enter their credit card details. Providing a meaningless 'security' icon was needed to bootstrap consumer trust in the industry.