Root certificates aren't useful either unless users install them. On the other hand, private keys of SSL providers can be of use for serving false certificates, but that's only useful if you also MITM.
As of writing this message I currently have over 170 root certificates on my macOS. Some of them are from companies who are known to care very little about your privacy. There's even a "Federal Common Policy" certificate which is actually run by the US government [1]
If the government did MITM you're traffic, it would still show in the certificate chain. But how many people really check this every time they visit a site?
2. Regardless, Certificate Transparency means it will almost certainly be noticed.