Also, if someone hijacks my provider's DNS server and resolves cia.gov to a different IP address, TLS/SSL will inform me of the signature mismatch, so you're wrong here as well.
Also, if someones hijacks my DNS and resolves cia.gov to a different IP address, TLS/SSL will inform me of the signature mismatch, so you're wrong here as well.