Seems they're between a rock and a hard place. When Google proposed HTTPS everywhere, a number of people took exception because not all content has sensitive data needing protection. I guess the real question is whether an HTTP call to load an ad copy is sensitive content. I think you can make an argument that it is sensitive content, because if I were monitoring your connection, and everything was encrypted, but I s…
We've moved passed the idea that only sensitive content needs to be transported over SSL/TLS. https://www.amnesty.org/en/latest/campaigns/2015/04/7-reason... https://www.aclu.org/blog/you-may-have-nothing-hide-you-stil... http://www.ted.com/talks/glenn_greenwald_why_privacy_matters http://falkvinge.net/2012/07/19/debunking-the-dangerous-noth... https://en.wikipedia.org/wiki/Nothing_to_hide_argument
https://citizenlab.org/2014/08/cat-video-and-the-death-of-cl...