TLS means dick if you have a nation-state that can mint a cert that would be trusted by your browser. Unless you're using a site that does cert pinning (which is basically a list your browser has of URLs and expected cert fingerprints as published by the site owners) or the fuckery that Google gets up to in chrome (they monitor and immediately ping the mother ship if a Google property is detected using an unauthorized cert), you can't really stop or detect it as an end user.
Your computer trusts so many companies to vouch for other sites' legitimacy that it's not out of the realm of possibilities that they leaned on a CA and minted a cert to let them MITM the connection. You're still connecting to a "trusted" cert, even if it isn't the legitimate one.