Earlier quoted context omitted.
> Tell me how the logic works here (for an average user). "Neutral Chrome" is the default state of the web -- the site doesn't assert that it should be trusted, and it shouldn't be, and that's the default state people should have in approaching the web. "Cool Green" is "the site asserts that it has a particular identity and that communication with that identified site is private, and it passes the tests built into th…
Plaintext is zero security. Self-signed is a low probability of security. Signed is a high probability of security. This continuum makes more sense than the current state of affairs.
If someone forwards encrypted content on behalf of my server, it's called man-in-the-middle attack, and they should not be capable of doing it without the huge red flags.