When Let's Encrypt eventually stops behaving in an altruistic fashion, we'll stop doing near-mandatory TLS.
Regardless, for HTTP there's an entire 'year 2000's web' worth of people out there using browsers that can access the non-corporate web. As the corporate web diverges with things like stateful HTTP extensions, UDP HTTP, and CA TLS only implementations (if not spec) there's no need to switch to a niche protocol like Gemini. Just making a normal website on the web is enough to bring back the old small web environment. As a human person not operating under a profit motive and just doing things for kicks this is just fine. A silver lining like how usenet is actually good again now that most people don't get it from their ISP.
Their root CA can't really be revoked either unless you want to turn off most of the internet. Not that big CAs would ever suggest anything like that in the name of "security"
Was that because the government mandated that outcome?
Has it really been so many years since people used to do tcp injections and walk around coffee shops or whatever returning results faster than the internet server and injecting goatse?
You guys have forgotten who tls protects.
The risk comes from the absolutely bonkers corporate/institutional use cases of automatically executing all random unverified programs sent to you. When you remove this crazy use case suddenly all the problems (and bonkers requirements) go away.
Seeing a goatse is not the end of the world and actual MITM injection attacks like you describe are rather rare now. I miss when wifi use to be open and that issue mattered.