An HTTPS only standard is not going to mitigate MITM attacks which is invariably the biggest issue regardless of perpetrators although this is clearly a step in the right direction.
Proper HTTPS is secure at MITM attacks. HTTPS can be MITMed if the certs or local systems have been breached. But the MITM is just a byproduct of a different failure. Absolutely any secure communication protocol has to be honored by both parties for it to be secure.
I think preventing MITMs when you don't have control of the local systems or network architecture is important.
But it's impossible. If I'm logging your keystrokes, game over. Unless you add some firmware to do dsa encryption in your brain, and become very fast at typing cyphertext.