The problem is that browsers might not ever implement anything like that, even providing an unobtrusive danger warning, because so many everyday users would be scared by it or assume their browser is "broken" because their last browser didn't do that on most websites.
Regardless, that really should be the default behavior. There's simply no excuse for not providing an encrypted connection. It comes with virtually every web server out of the box.
What I meant is that you can use a self-signed certificate, which is takes seconds go create. Some server software will even do it for you if I remember correctly. If this is too had for someone to implement, then they really have no business building web apps.
In a world where unencrypted connections are scary and an encrypted but self-signed connection is treated like HTTP connections currently are(not scary), it only makes sense for people to support HTTPS. There's nothing inherently hard about implementing an HTTPS service beyond one extra initial step.
Beyond that, there's LetsEncrypt, and services like AWS will take care of creating signed certificates for you; I imagine they aren't the only infrastructure host that does this.
Its use in every situation (ie, browsing a website dedicated to reviews on salt shakers), might not be necessary and could cause an affect similar to the overuse of antibacterial soap. :p
It will also prevent older computers from accessing the web as ssl standards evolve, which is kind of a shame.
> It will also prevent older computers from accessing the web as ssl standards evolve, which is kind of a shame.
At what point should an older computer no longer work with the current web? Eventually there's going to be a breaking change. A computer old enough that its browser can't be updated is probably vulnerable to all sorts of browser-based attacks.
FWIW the trend has been ongoing for a long time. I remember 10 years ago being frustrated I couldn't scp with the NULL cipher on my own local LAN unless I built from source.