If everyone had their own simple blog (or plan file) instead of Facebook/etc, I think the world would be a better place.
I can't wait for the pure hell that is captive WiFi once browsers provide sufficient friction to accessing non-HTTPS sites. Most devices are good enough at popping up the portal but far too often I find myself pulling up http://neverssl.com to force things to start working.
HTTP is here to stay. Maybe browsers on PCs will make accessing it extra hard, though I suspect that's untrue as well (maybe POSTing data to HTTP web sites will be harder in that people will see extra pop-ups).
But sites which have lived as HTTP forever are not going to magically get some maintenance done on them to move to HTTPS, and people will still visit those web sites.
And let's talk about all those crazy cheapo IoT devices that are already spreading through the world that have their "http" servers hard-coded.
Don't get me wrong, I've been on the HTTPS bandwagon since forever (before LetsEncrypt, the best deal you could get for multi-domain personal webpage certs was StartSSL, an Isreali company with very buggy software that you had to fight to get a cert issued). And I've long (decades?) advocated that browsers should first try an HTTPS page when protocol-less URL is given (which they are only now moving to, duh?).
But I'm not even talking about desktop browsers, here. It'll start with mobile devices. iOS and Android going HTTPS only with their default browsers is entirely within the realm of reason. Flash was functionally dead once Android gave up on it within a few years. Yes, there was a long tail of enterprise users and people who refused to give it up.
Similarly, there will be a very long tail of HTTP. But Apple and Google are in a position to kill it just like they did Flash.
Even with mobile devices, I imagine another cycle is coming where people care more about what their seemigly-general-purpose computers restrict them from doing.
But I'd still wager that it ain't happening in the next 3 years.
In the fee paid for the domain name, the owner should get perpetual free secure DNS and certificates for any purpose and sub-domain.
The current issuance of (non-EV) certificates is an unsecure hack over DNS anyway[1], so why not merge certificate issuance at the protocol level?
[1] https://en.wikipedia.org/wiki/Domain-validated_certificate
But that can quickly become impractical. I run a bunch of small personal web sites (different domains) on a single IP, which a certificate is tied to (since HTTP "Host" negotiation only happens after the encrypted connection is established). I think there were changes to allow this negotiation to happen before encryption, but that loses some privacy.
I also use a couple of registrars, so coming up with a solution to this existing complexity is extra hard. Maybe with IPv6 where I can cheaply use a bunch of fixed IPs instead.
For the second concern, it can be in principle automated to the point where you only need to inform the webserver of its hostname(s). If the DNS A records are correctly configured, it's trivial for the DNS server to verify the IP address and sign the CRL generated by the webserver on the fly. Like a letsencrypt operated by your DNS provider that simply works.
If you aren’t using some centralized platform like LetsEncrypt, you’re lacking that layer of known trust that is required with the SSL system. It is not a trustless system.
This is a stupid idea, it means the browsers will not be compatible with old websites, if they drop http I hope they would first drop all the other old stuff that are bad and no longer cool.
A big warning should be enough, old websites should still work in a competent browser.
They have been doing this. Gopher, FTP, XUL extensions, NPAPI browser plugins, old TLS versions, for examples in the last few years, and alert()/confirm()/prompt() for Chrome's current push.
<rant> I'm actually looking forward for them to drop HTTP digest auth, because it's the only auth scheme which doesn't rely on sending shared secret over the wire with each request </rant>