> The push towards forced HTTPS has significant costs, which most people in this filter bubble don't want to honestly discuss.
I agree, but I'll push back by saying that delaying HTTPS adoption and getting lax about it has a much higher cost -- and that is similarly a cost that most people pushing back against HTTPS either downplay or refuse to acknowledge.
And more than that, those critics have shown that they're not interested in solving the problems that they bring up or in finding ways to mitigate them. So it's not like we can wait a year and adoption will suddenly get easier. The critics of HTTPS aren't moving forward. They don't want HTTPS adoption to slow down while they catch up, they want it to stop so that they don't need to move forward at all.
We've seen significant improvements in usability for HTTPS for ordinary people, from LetsEncrypt, to Cloudflare, to Netlify. Holdouts like Gitlab and Github don't provide an easy way to provision certs by default. A lot of other smaller hosting providers are ignoring the problem entirely. This will get better over time as more hosting providers realize that this is a feature they have to provide to be competitive.
But that's the thing. Smaller hosts are ignoring the problem and they will continue to ignore the problem until they're forced to upgrade their infrastructure to support solutions like Certbot. Because MITM attacks aren't their problem, client privacy isn't their problem. They are not going to get better support until they literally don't have any other option.
That changes our calculations; where a decade or two ago we might honestly argue that immediate, harsh incentives to switch to HTTPS had too many downsides, we're now in a position where we realize that harsh incentives are the only way that HTTPS infrastructure is going to improve at all.
And that has significant implications for people's privacy and security online. We're at the point where even though it's a barrier of entry for some people, everyone should still be using HTTPS on any public site that they build, period. Honestly, I'm in the process of trying to find good HTTPS schemes for intranet sites too. We need to move forward on security.