What are they even talking about? People can just casually decrypt https now? Isn’t the whole point of https that something like this can’t happen?
I always keep it enabled and there are almost no sites that require exceptions except on corporate intranet.