> We do the same for Facebook: Slotboom is able to intercept the login name and password I entered with relative ease.
That sounds bit too good to be true. Facebook uses HSTS with preloaded certificates. I certainly am not aware of any "relatively easy" way of circumventing that.
> Everything, with very few exceptions, can be cracked.
Bit unnecessarily fatalistic attitude imho.
TLS is still pretty solid. Almost any half-decent VPN is non-trivial to crack. While software has holes, zero-days are typically bit beyond "All you need is 70 Euros, an average IQ" guys, so keeping your systems patched is effective measure.
Not saying that downgrade attacks etc aren't real threats, or that you don't need to pay any attention. But you can be relatively safe with fairly basic precautions and the overall situation is improving, one example being the increased alerts from browsers.