Https

SSL > TSL is not as safe as promoted

certifcates work with public/private keys

problem are the CA Certificate Authorities , who you need to trust

They can’t ,
see as an example the Verisign - Symantec - debacle

if the certificate is

chromion has a build in certifcate , so that google.com at least will be always certainly

Brax.me has an a(? android ?) app : CatchMITM app , available in the aurore store
Quid linux/windows ?