There are multiple software packages that make it trivial to set up a rogue ap or attack a physical network (with say, arp spoofing). The same is true for proxies that will attack ssl by replacing any certs that it needs to.
These are not theoretical attacks. Any 16 year old with a $300 netbook can download software written by others and perform these attacks at your local Starbucks in a few hours. They would be able to see all traffic (even https) and without self-signed warnings the only outward sign would be the lack of the green url bar associated with EV certs.
But what is the resource cost to spoof a connection? Very cheap for a teenager to sit at Starbucks and spoof your connection, but how much would it cost when using a fiber splitter at AT&T in order to MITM billions of connections per day?
It would cost more to proxy a billion connections a day than to read them off the wire. But it would not cost so much more as to change the feasibility of the attack. At Internet scale, you may be talking about doubling the cost.
Meanwhile, the proxy attack is the gold standard on the actual Internet we all use. Sniffers are obsolete.
These are not theoretical attacks. Any 16 year old with a $300 netbook can download software written by others and perform these attacks at your local Starbucks in a few hours. They would be able to see all traffic (even https) and without self-signed warnings the only outward sign would be the lack of the green url bar associated with EV certs.