Also, consider your risks more holistically:
* Honeypots can and do have valid https certificates, what matters is who controls the site (for example, when the FBI took over a kiddie porn site, it changed the site to deliver over https a zero-day exploit for Tor Browser that broke out of the browser sandbox and deanonymised the visitor) * Eavesdroppers can tell you visited a specific HTTPS site by looking at your TLS1.2 SNI in cleartext. Even if you're using TLS1.3 (which fixes that leak, but is currently up to the browser/site to negotiate), eavesdroppers can still correlate site access with your DNS requests. Even if you use DNS-over-HTTPS/TLS, you don't know if your DNS provider is in cahoots with the eavesdropper. You have to trust someone
Where your actual risks lie in visiting an HTTP-only site:
* If the site has forms/cookies, an eavesdropper can see them. In this case, https buys you nothing; your concern is that someone can tell if you visited this site once, not that they can tell you're a repeat visitor * Eavesdroppers can see any headers that your browser hands out (mainly user-agent) that could more granuarly identify you vs just your IP address * Active attackers with the ability to control your traffic can place anything they want on the website by spoofing its responses. With https they could only deny you access to the site
The benefits of HTTPS over HTTP are enormous, but you have to understand what its limits are. If you're concerned about web surveillance, you should be something like Tor Browser to visit websites, and understand that even it has limitations.