If you're using plain HTTP, someone can MITM in HTTP, and a rogue authority can issue a certificate to someone who isn't you. This is not an argument against you using HTTPS at all.
Self-signed HTTPS would be even better, but it seems to be frowned-upon by browsers these days.
Absolutely not. I am pointing out that even within your (incorrect) assumption, you using HTTPS does not hurt your security at all.
That you take it to mean "HTTPS is insecure" is your own assumption, that you take it to mean "equally as insecure as HTTP" is something you made up.
A parallel: A lot of companies make seatbelts, you're not sure you can trust all of them. Even though they would be caught by quality testing and instantly go under, it is possible that one of them would build them with cheap materials that wouldn't offer much protection. Therefore seatbelts are not completely safe. Therefore wearing a seatbelt is equally as safe as not wearing one.
For Google this is fixed by hard coding the SSL hashes into chrome, for the rest of us we rely on http headers; which of course are much more fungible.
Maybe with DoH it’s better. But that’s more https to make https not suck.
Disclaimer, I didn't know about them either. TIL.