SSL certs require cooperation of a trusted registrar even for the biggest companies -- Google's is signed by Equifax, for example. Given what we've seen in the last few days, requesting keys from the root CAs is a no-brainer.
For Tor, a bunch of attacks are possible by owning only a small percentage of all nodes. Recently, Tor was issuing a "call for relays" due to a dwindling number of participants that was endangering the network. Considering that Tor came out of Navy research, if you don't think they have a statistically interesting number of nodes, you're crazy. If they don't, it's only because they don't think that Tor is an interesting source right now.
TL;DR: Security depends on your threat model, and while I think that Tor and HTTPS provide strong protection from run-of-the-mill attackers, I don't think that either provides meaningful security if you're worried about the NSA.