i have had trouble with understanding the push for EVERYONE doing https even in localhost because "security". boo.
i live in a place where by law ISPs need to have DPI. they can access any communication regardless of SSL or https or anything in between so why should i bother with the added nonsense of "much security" when it is not supposed to even work?
i understand there are attempts to make https to be as transparent when it works but why should that not be restricted to banking transactions or login pages and payment links? again, DPI.
now this cyber resillience act which i am assuming wants to "security".
what kind of security?