You can't assume protection, whereas with http you assume no protection.
So, if you can't trust certificate (not when it is invalid), just show same level of protection as http.
So, if you can't trust certificate (not when it is invalid), just show same level of protection as http.