It would be OK if browsers treated self-signed certificates a little better. There are lots of contexts where a self-signed, long or non-expiring certificate makes perfect sense. But browsers and security stacks in general react as if the whole application is broken, just because they didn't see the certificate before - even when they have no evidence the certificate is malicious. SSH does it nicely, with a prompt on first use and then detecting tampering after - why has this not been adopted for TLS?