> Other than shopping privacy, who cares? As long as the checkout and account management pages are https, then I don't see the big issue here.
Please understand that you are wrong here.
You need to go and read the article, and then perhaps some more writing around why it's important for the whole site to be served over TLS.
Once you can read and understand the linked article and why what was described is a real issue you will no-longer sound like you don't know what you're talking about on the Internet.
> I'm just not one of these people who think there are armies of people at the NSA/GCHQ spying on me.
This isn't about NSA/GCHQ, it's about "bad actors". Which bad actors are relevant depends on your circumstances. It's quite likely that the bad actors in the case of maliciously tampering with the login links of a bank, or the link a checkout process on an e-commerce site will not be a government entity, but a criminal operation.
> I'm also against forcing every website in the world onto https.
It's really not that hard to implement TLS on the average website, and the benefits are great.
However the main focus of this article was about TLS on sites that link to sensitive information, such as banks.
> Doing so will significantly raise the bar of accessibility for tinkerers and makers.
There's two things wrong here.
1. It's really not raising the bar very high. Lets encrypt is easy to use, and as a member of a hackspace myself I know that most people there could use it, or get help using it.
2. Just because some "tinkerers and makers" may struggle with some aspect of security doesn't mean that e-commerce sites or banks etc. need to downgrade their security, or that the rest of us need to suffer.
> If I had a webcam that showed the world whether my coffee put needed refilling[1], are we all saying (on this thread, and troy hunt) that it needs serving over https because the privacy and security of coffee watchers is such a closely guarded secret that they need to be secure in their coffee pot watching habit?
This is a straw man argument. We're not talking about, and likely don't care about, your coffee pot.
We do however care about not having our personal data intercepted, our identities stolen, our credit card data misused, or ourselves be profiled etc. All concerns with things like e-commerce, bank, news sites etc. etc.
> By all means, https up important pages and sites, but lets not make it mandatory to the extent that http is no longer supported by browsers.
Ultimately this may happen in the interests of everyone's online safety, and when it does there won't be some sort of "end of times" scenario where coffee pot sites are dissapeared from the Internet, people will just move to use TLS on them.
> As an aside... a Barclays bank advert running in the UK at the moment is showing users that 'a padlock in your browser bar ensures that you are safe and that the site you are visiting is who you think it is' - which is utter bullshit, all a padlock tells you is that site owner has spent 5 minutes setting up LetsEncrypt - it in NO way confirms that they are who they say they are, and it's this lie that Joe Public are being sold right now.
Yes, and it's typical of banks to get this aspect of security wrong, however it's still better than not having TLS, and at this point you're just going to have to go and work out why yourself because I have other stuff to do.
> [1] Apparently this was a thing once ;)
Yes, it famously was: https://en.wikipedia.org/wiki/Trojan_Room_coffee_pot