Things like this are going to force a confrontation at some point. Either the existing programs for monitoring people are going to become progressively more useless as people switch to HTTPS for example, or the government will insist very forcefully to get access--getting private keys from certificate authorities, for example.
Well we effectively 'won' the last major confrontation (crypto code) so a confrontation is not bad per se.
However this does mean that systems like PRISM and phone metadata will simply become more important as 'upstream wiretaps' go away, and the NSA will surely have other tricks up their sleeves as well.
Of course, anything we can do to make their surveillance efforts require manual intervention (e.g. having to attack an ownCloud installation from within a rented system in the same datacenter) makes those efforts less of a threat to each of us than a completely automated tracking of anyone they wish.
And more worrying than even that, with the top four browser vendors all US-based, would pressure be put on them to not remove the root certificates? That, IMO, is more worrying than government interference in CAs: the system is designed to work around government interference in CAs (by removing the CA root as trusted), but isn't so capable at dealing with government interference of trusted roots.
Due to Firefox and Chromium both being open source, this won't be an issue. If the browser companies remove the ability to remove root certs, we can just fork and add it back.
This isn't a technological issue, it's a political issue. It requires a political solution, since laws can be enacted to make what you're proposing illegal.
The hacker mantra is indeed "There is a key to every lock" but what happens when 1) you unlock a door, 2) they know you unlocked that door, and 3) it's illegal to unlock that door?
A hacker charged with changing YOUR Internet Browser, potentially making the entire country less secure in the face of terrorists, has been found guilty of crimes against the state.
How about Hacker Jailed For Shipping Web Browser With Secure Encryption? That sounds crazy, no? Yet the US has limited availability of encryption before, so why should it not do so again?
What law would be so dumb as to force an American browser to include malicious CAs, publically, and not also force everyone to only use those American browsers?
In your imagined dystopia what you're talking about doing (using a browser with safe CAs) would be illegal no matter where the browser really comes from.
It's no different with locked-down phones/tablets where it's illegal to root it. You don't need to force everyone, just people using American ISPs/carriers.
That's not the issue. The issue is the majority of browser users will use the default set of root certificates. Forking and removing them is the least of the difficulties; getting people to use the fork is the problem.
Oh, sure, some may know enough and care enough to do something about it, change browser, change root certs — whatever is needed. But this isn't about them, this is about society at large. This is about whether your mother, your father can use their webmail account without being spied on: would you want all your emails to and from them available because of a MITM attack on someone who is not you? (I realise email is not a great example, with emails typically being transmitted in plaintext between SMTP servers, but is reasonable in the generic digital communication sense.)