> A proposal then is to do HTTPS everywhere in the sense of the protocol but not the URI prefix. A browser gives the secure-looking user interface message, such as displaying the server certificate holder name above the document, only when the document has been fetched in an authenticated over an encrypted channel. This can be done by upgrading the HTTP to include TLS in real time, or in future cases by just trying encrypted version first.
He also states
> It is the user's task to ensure that their interactions are secure.
meaning, users are trained to look for the 's' but browsers are hiding the URI prefix, making this difficult.