I still contend that "everything should be encrypted" is cargo culting:
An unencrypted webby stream does not expose a browser to anything nastier than an encrypted webby stream. The eventual payload is the same, regardless of the transport. The difference is that the browser has to use vastly more code paths to do the same job of receive -> display. It has to decrypt the stream. That additional complexity introduces vastly more possibilities for bugs.
So, I think you should pick your medium with care. I do think that https is a safe transport for all messages and do routinely use it myself. I have done a risk assessment on it - I don't simply use it because everyone else says its a good idea 8)
I deliberately used the pejorative term "cargo cult" in this discussion.