Broadly speaking, we should. And that's why there's been a lot of work lately in doing things that either build on or bypass the CA system. For instance, even if you get a valid CA certificate for a site you want to spoof, it still has to be a different certificate, so there's more work on certificate pinning. Sure, that doesn't help if the spoof cert is up the first time a given person visits a site, but it still raises the bar for successfully attacking a site surreptitiously, because anyone who hits the site post-pin will get a big warning, which can be picked up with other things. Now the attack has to be even better targeted.
And there's other work going on lately, and while it may not be immediately visible to the general public because this all takes time, it really seems to me this has all gotten a lot more vigorous over the last year. I don't even think it's all Snowden per se... it seems to me generalized security consciousness has gone up lately, like we passed a critical threshold of people's work feeding back on other people's work and the community as a whole has moved to a new level of effectiveness. It'll still be a while before we really see the changes but I think some changes are coming. (Not Utopia. We've still got a long ways to go. But some general improvements.)
I think in general https would work against this particular attack, if you don't accept sites with mixed content (I am not aware of any browser plugin which does suppress plain content on mixed sites).
As a matter of observation, it is kind of amazing how short of a memory even the internet has. It seem to be a knowledge management issue, i.e., new and evolving information is not contextualized or even related to pertinent past information.
Creative use of advertising platforms is used you could easily narrow targets down and guarantee that you know exactly what the content is.
Anyways, this is just one gadget.
A single request going through a bogus certificate emitted by NSA "acquired" CA would be hardly detected.
Or, given the fact that they could indeed broke keys, they could simply do a man-in-the-middle, instead of a man-in-the-side.
There are browser extensions that detect bogus certificates; there's a good risk of catching them.
Sometimes they keep this box offline, but they need to keep a sub-CA online somewhere, or they wouldn't be able to issue certificates.
So, a CA private key and public certificate can be compromised in much the same way a single server certificate.
With a CA private key and public certificate, one can easily emit a bogus certificate for *.google.com or any other domain name. If this CA public certificate is trusted by the browser, a user would hardly notice.