Thus without any additional configuration, the data sent over those connections would be safe.
Thus without any additional configuration, the data sent over those connections would be safe.
Very technically this would be slightly better because it stops passive observers, but in reality I suspect it would be worse because tons of websites would use this broken by design solution and think they were perfectly secure because encryption.
What we really need is to stop making HTTPS so hard to setup. It has gotten better in the last 5-10 years, but you still have to do this whole rigamarole with Apache2/nginx to disable weak cipher suites, setup all the right TLS parameters, etc because the default configuration is so bad. Imagine a world where I just installed an HTTP server and it asks me if I wanted to get a cert from Let's Encrypt (or any other ACME provider) and just did all the setup correctly for me.
For example, if there were a class of websites where certificates were not checked, I could configure my router to man-in-the-middle attack every connection to one of those coming from anywhere in my own network, and then re-transmit information in the clear somewhere else. To someone inside my network, their browser would report their connection as being "secure".
TLS does try to provide confidentiality and part of that is authenticating who you are talking to. Without this your communication is not at all confidential, as anyone could impersonate your intended target. A passive adversary can't read your traffic, true, but an active attacker (of for example the coffee shop dwelling variety) is not a major step up and would undermine the confidentiality aspect entirely.
That is exactly what Caddy https://caddyserver.com/ does - except it doesn't even ask. Automatically setting up HTTPS is the default, zero-extra-configuration behaviour.
You buy a few and take your Tylenol without a second thought—right?
Maybe not. If that seems ill-advised, please don't propose the same for websites.
Tofu, like with ssh, is a valid strategy. Trusting third party providers is decreasing safety compared to only having you and the service.