As a UK citizen, I now do not regret in the slightest forcing every single user of my website to use HTTPS. It costs maybe 10 or 20 dollars a year, your site runs no slower, and all your users get real privacy.
Sorry to spoil it for you, but HTTPS provides no protection against MITM when the MITM is a nation state which can legitimately buy root keys from CAs (or become a CA themselves, if they are not already).
Well, you can verify the certificate is the same when accessing the page via your connection and via tor. If they have different chains you stop trusting the root authority.
This can be spoofed only if the nation state buys the master root keys (i.e. not just a key allowed to sign any domain, but the root key the provider uses to sign everything, so that the chain is exactly the same) from every certificate provider... At which point you're screwed whatever you do.