There really is no absolute right or wrong to this issue. HTTPS is indeed more secure for users, but it does have some cost, and I think OP has a sensible argument. If you really think HTTPS is the best thing ever and is absolutely better than HTTP in every sense, you're just looking at it superficially. When you start looking into how the entire Internet works and what role each party plays in the ecosystem, and how…
you'll find that HTTPS is THE biggest centralization force of the web This, very much this. Plaintext doesn't require what is essentially authorisation from a central authority in order to communicate.
- Your address needs to be given to you by your ISP or ARIN.
- Major ISPs need route to your address and/or accept your BGP announcements.
- You probably need a name which is bought from a few large DNS management companies or their resellers.
- You're required to have an email address to field abuse complaints which means you most likely will be paying an email provider.
- If you're not running your own hardware you will have to pay a hosting company.
- If your site is large you'll probably need a CDN to handle the traffic of which there are only a few major players.
- Although it's a blacklist you effectively need Google's blessing to not appear on the SafeBrowsing list.
Is the CA system really that much more of a hurdle? No question it's a little scummy at times but it's cheap and relatively low maintenance.