Earlier quoted context omitted.
Ok, so it's just a horrible user experience then :]
Exactly. Worse, it trains users to ignore cert warnings. I don't have any problems with the campaigns to make the public internet HTTPS-only. However, for software inside an intranet, or software that just wants to expose an interface on http://127.0.0.1:*someport* non-SSL is the better default. If people want to protect their intranet that's great, but it means that they have to go through the work of buying a cert,…
Nowadays, I'm a firm believer in "encrypt all the things", but that's because I'm a geek and can deal with the PITA. There needs to be either an encryption mechanism that's completely separate from authentication, or the use case of LAN encryption for regular people needs to be addressed in some other way.