He might disobey a personal gag order, but I can assure you that as long as PRISM exists, U.S. companies will comply if targeted.
There are also plenty of other attack vectors for the NSA even with HTTPS; obtaining the private keys of the common certification authorities is perhaps the most straightforward.
There are also plenty of other attack vectors for the NSA even with HTTPS; obtaining the private keys of the common certification authorities is perhaps the most straightforward.