How easy is it, in practice, for a nation state level authority to add a root certificate to people's devices?<p>Adding letsencrypt to my personal server made me realize that if I'm MITM'd by a proxy, the padlock still shows up; merely clicking on it and going down a couple of menu levels (in Chrome "Connection is secure -> Certificate is valid" will reveal that the MITM proxy's root certificate is in use.<p>If an employer can do this to its laptops, and presumably a cell phone maker to the cell phones it sells, just much protection does https really give you against a nation state level propaganda machine?