Earlier quoted context omitted.
I would hardly call it secure. There have been too many failures with certificate authorities. The whole system is dependent on that weak point. Also do you keep track of the certificates issued to every website you visit? Then if you visit the website notice the certificate has changed. Do you check if it's a legitmate change ect.. If you don't keep track of certificates how do you even know you are not being MITM.…
> I would hardly call it secure. There have been too many failures with certificate authorities. The whole system is dependent on that weak point. Just because a system has flaws doesn't mean you should be using an even more flawed system like HTTP. With HTTPS, attackers can't read or modify traffic. If you really think certificate authorities are that unreliable, you can choose which certificates you trust yourself…
However, my problem is the browsers are forcing choices on people that are not part of the standard. They are acting as if they know best. They are also making it harder for advance users to alter these decisions. Try to enable plain text HTTP 2.0 in Firefox? No option exists in about:config.
Further, I don't see an option to disable Firefox's Secure contexts for new features. Might exist, but may need to look more.