Meanwhile it's 2026 and Greg's own website still doesn't support TLS.
In addition even without bad actors TLS will prevent random corruption due to flaky infrastructure from breaking the page and even caching those broken assets, preventing a reload from fixing it. TCP/IP alone doesn't sufficiently prevent this.
Why do you allow that RCE in the first place?