But that's when using the Nokia, Opera, or Amazon browser. If you're worried about Nokia, Opera, and Amazon facilitating MITM attacks, they could also just program the browser with a secret NSA certificate authority.
>they could also just program the browser with a secret NSA certificate authority.
I strongly suspect that NSA don't have to do that kind of stuff that can be easily noticed. They just ask nicely from Symantec/Verisign to give them valid certificate. Or they already have common root certificates.