That's far from being the only encryption system available - SSH doesn't even have a concept of "root certificate" to MITM with.
And it's not as if they can do it secretly. If they suddenly started to MITM all TLS traffic in the country by replacing the certs with certs signed by the national root, it would get noticed within minutes, if not seconds. And God only knows how much stuff it would break. And on top of that, they don't even have the capability...
There is 0% chance they would attempt such a thing. And 100% chance that such a thing would fail immediately and fail badly. I don't know why people think there is even a slight risk of them trying such a thing. There isn't.
Who can resist a sufficiently determined state that still enjoys popular support? All he has to do is engineer the support for "security" over the long term.
Don't misunderestimate your fellow voters.
[edit] https works based on trust. We trust the browsers and OS vendors to at least try to prevent the CAs from abusing their power. As soon as it becomes obvious that the OS and browser vendors are now letting state actors compromise all traffic, then https is dead in the water and something else will come along. Nobody is going to risk that happening. It would cost too many rich people too much money.
I had little interest in security before Snowden, so admittedly, I need to lurk moar and keep learning. Thanks for offering another argument I can try to fit against new facts I encounter and helping me continue that process.