I run a service that involves adding Javascript to a site (like you would with Google Analytics). At one point we were serving 100% of scripts / APIs via SSL, but ended up moving to matching the origin host's protocol because customers were complaining of older version of IE that actually block HTTPS requests that originate from HTTP pages.
So now we serve API calls matching the protocol of the domain the script is loaded on.
It's been on our mind to go back and figure out exactly which browsers this affects, implement browser detection logic, and then serve SSL APIs for everyone else. Although it's a bit tricky when supporting customers who have users (still) accessing them with obscure / old browsers.
More broadly, Let's Encrypt has been a great initiative. AWS WAF is also great for generating certs easily (although only inside AWS unfortunately with specific AWS services). Initiatives encouraging people using legacy browsers upgrade to upgrade will also help companies like ours (and others) trying to support 100+ browser versions on various OS's.
For us, China has also been a slight issue. The firewall tends to add extra (unpredictable) latency for SSL requests, even when engaging with firms for $xx,000 specializing in overcoming China networking related obstacles.