A centralized cert is just that, centralized. Even if it's LetsEncrypt that's still a single point of failure for organizational corruption (ie, what happened to dot org), accidents (as cert providers mess up regularly) and government control. It's a long leash but if HTTPS is the only option (as is the trend) it's still a leash.
Almost all sites should be HTTP and HTTPS.
> Almost all sites should be HTTP and HTTPS.
This. Most people aren't even aware that Google.com is still both HTTP and HTTPS; you can easily test with curl or lynx to verify yourself. If your browser doesn't support HTTPS (e.g., maybe its blocked in your library or another free wifi), then Google.com would still work just fine. (Another question is that many other sites aren't as easily available, sadly.)