Like it or not, it is up to the information owner to determine their threat model and which mitigations are suitable for that threat model. If someone is broadcasting a message containing information that is public, they may not consider someone intercepting a response and altering it to be a threat that needs addressing, or they may consider alternate mitigations as sufficient -- e.g. the fact that many people can independently verify the information from different sources. For the vast majority of sites, this is a reasonable assumption. Just because you may be worried about this threat doesn't mean the information owner needs to be. Of course you as an information consumer have your own threat model, and if you are really worried about someone targeting you and altering http responses sent to your browser, then you may not want to visit unencrypted sites. That is also legitimate. The information owner can't force their threat model on you anymore than you can force yours on them. But words like "secure" and "insecure" make sense only with respect to a given threat model, they are not attributes of an http connection.