TLS is transport encryption, not a content signature.
Ideally, I'd like to see every resource being served along with a signature verifying its authenticity, origin, and suitability for public consumption.
Users would then be empowered to make the decision whether we wanted to interact with a resource that does not offer these protections, and assume the risk, or simply refuse to load any resource that doesn't positively identify where it's coming from, who made it, and who certifies it as worthy of your consumption.