Yes, it's really a broken system by this point.
There are two alternatives to someone who wants to be a little bit safer:
1. Use something like Web of Trust. At least you have the power of community
to back you up.
2. Test the site fingerprint manually in https://www.grc.com/fingerprints.htm
Yes, you are still trusting a 3rd source, but at least you can check if there
is anything suspicious....
So, yeah, I don't really think https is anywhere as safe as it once was...
But it still provides some good protection (at least it's harder for a
cracker or for your ISP to spy on you than if you were running simple http).
I wonder, could one make a addon for abrowser that would check the
certificate AND the fingerprint in GRC? That would double the protection.