Your reply doesn’t have the facts I have asked for.
So let me share what I know on why the encryption everywhere skyrocketed, and hopefully it is useful for anyone. It’s long and has some detours, to convey my point (which is outside the simple “encryption is good”/“encryption is bad” dichotomy) better.
In 2014 Snowden released the famous papers about the NSA snooping.
Following that, the IAB (the Internet Architecture Board in IETF, not to be confused with Interactive Advertising Bureau), prepared a statement here: https://www.iab.org/2014/11/14/iab-statement-on-internet-con... - which specifically mentions https://www.rfc-editor.org/rfc/rfc7258 also quickly prepared during that IETF meeting.
“Let’s encrypt”, although pre-existing, was publicly announced at the same time:
https://en.m.wikipedia.org/wiki/Let%27s_Encrypt
And due to its simplicity and being free of charge you can see the stats counting up pretty happily, and it is the reason behind the current abundance of TLS: https://letsencrypt.org/stats/
In parallel, the above mentioned statement also helped ensure the http/2 and later being fully encrypted with very little being exposed. However, I return to this later in (X).
This is the factual real reason behind: the widespread agency surveillance, the revelations of which was the straw that broke the camel’s back.
There were always “evil ISPs mangling the traffic”, but they were never enough a big deal (because as I said - it’s just few disjointed industry anecdotes, and you haven’t given any factual references otherwise).
With the stated goal of encryption in transit being a barrier against the state pervasive mass surveillance - it arguably was a successful measure and I am willing to say the complexity is worth the goal.
It still doesn’t change the fact that the endpoints (and due to complicated nature of HTML/JS/CSS - much more than your expected endpoints) have the full access to your data under the encryption.
So my viewpoint is your OPSEC should not change on whether there is transport encryption or not - there were and they are the actors collecting your data; they are just different.
If you specifically become an object of interest for the government, your data will be copied and analyzed. And the endpoints will be subpoenaed for the decrypted data/metadata. Pretending now things on the web are magically “secure” without these caveats is not responsible towards the users who don’t know better. Even the TOR, which is strictly stronger measure than a simple transport security, has caveats: https://tor.stackexchange.com/questions/7339/what-metadata-d...
(And I am not sure whether a simple img src on an .onion site to a non-onion source will leak your real IP these days but it was a valid attack vector at some point).
In that regard it can be argued that if your OPSEC is “trust as if all the data you send is being monitored by all possible adversaries”, then absence or presence of the encryption doesn’t matter much, and it is what the proponents of “no encryption” are saying.
(X) there is a reason involving the “evil ISP sniffing the traffic”, which http/2, formerly known as QUIC, tackled: and this is about the protocol evolution. The early internet protocols were fairly easy to snoop and man-in-the-middle with, and this gave the grounds for two kinds of devices:
1) “tcp protocol optimizers” for connections with crappy UX like satellite (huge RTT)
2) bandwidth policers. Pervasive use of poorly written p2p file-sharing apps by the internet users clogged the pipes for the ISPs, and made the more “polite” TCP traffic used by the vast majority of the users perform much worse - so it was a question of their service continuity to do something.
Since then, LEDBAT working group at IETF has tackled that at the protocol level, but something had to be done “in the moment”, and there were companies who made a good money on selling these kinds of boxes.
These both were a fairly widespread practice probably all the way before 2010, and made it almost impossible to do any modifications to plaintext internet protocols without breaking some faulty assumptions by the deployed middle boxes and thus making said evolutions impossible to deploy. (A small, much more obvious example is the widespread usage of transport-leaves NATs prevented the deployment of SCTP at internet scale until (too late) when it got UDP encapsulation…)
So, while technically it is the “ISP meddling with the traffic”, it was done for a completely different set of reasons. (As for the ISPs doing Lawful Intercept - it didn’t go anywhere with the advent of the encryption, see https://en.m.wikipedia.org/wiki/Communications_Assistance_fo...)
(Edit: formatting).