If you go down this path you argue desktop browsing https is broken, which i dont think is a serious argument.
Notice my wording above - fundamentally broken in multiple ways - by which I mean that there are clear and articulable flaws with the model. Nonetheless it's clearly quite functional in practice.
https (specifically the CA chain of trust) is imperfect, and can be compromised by well-placed parties.