Earlier quoted context omitted.
> which can easily be manipulated to provide a copy of all messages to some convenient third location. Updating others javascript as a proxy isn't "easily". Also if the government goes all this way to tell each internet provider to spy on people, why do you think they couldn't tell certificate authorities to spy on people? It is the same level. I wouldn't be surprised if many CA's in USA already does this.
It is "easily", because current commercially available "firewall" appliances include that kind of capabilities. Just a few clicks, install a CA certificate, add a logging endpoint, done. Certain regulated industries like finance and medicine are required to use those. All chats are instantly intercepted and logged. And the way to spy on people via a certificate authority is exactly as described, you get a CA that sig…
If this means users gets more power over what CAs to trust then that is a good thing.