I can't work out how to not make this sound almost infinitely cynical, but their ssl key expires in 13 days - they only had to shut him up for another few weeks and they could have pretended they weren't currently MITM-able:
Not Valid After: Thursday, 31 December 2015 11:00:00 pm Australian Eastern Daylight Time
Maybe they'll upgrade it to something better than: Signature algorithm SHA1withRSA WEAK