yup. I'm sure the one dude responsible for it will get to it on Monday.
The certificate is expired, your traffic to and from that site is not encrypted. If it were the case that your traffic could still be encrypted, what would even be the point of expiring the certificate?
You're correct that you can still access it, over an unencrypted connection, however.
If that's the case, then Google's condescension is doing a disservice to its users.
<bold>Your connection is not private</bold> Attackers might be trying to steal your information from expired.badssl.com (for example, passwords, messages, or credit cards). Learn more about this warning net::ERR_CERT_DATE_INVALID
Just throw in a big red exclamation point on top of the little padlock icon next to the URL bar - it's literally only there to inform the user about any potential security issues. Use it and (unless the site is known to be or obviously malicious) load the bloody page.
Honestly, it's absolutely insane that the browser misrepresent out of chain HTTPS as more of a threat than HTTP.
Seems fine.