tls1.3 you can fully mitm with nice green padlock, its much easier if you have access to CAs where most big 'trusted' are US based. that being said a lot of govt for their services use their own ones and what is trusted and not trusted in CA land is highly dubious at best. try looking at all those weird nooneheardofthem names in the CA bundles on modern systems.

besides that its quite likely they will have intercepted most key exchanges since thats still a problem and pretty easy to see happening if you say, tap the backbone -_-.

US and few other have really futuristic capabilities here. its hard to imagine snowden was 14 years of secret innovation ago... it has only gotten much worse friend.