Yet another reason blindly running javascript from unknown parties is a bad idea. Whitelists for progressive enhancement I want should always have been the default.
I don't like "force HTTPS everywhere" but these jerks are forcing it. It sucks, but it sucks less than this.
1. Certificate problems with embedded devices.
2. Much harder to control what's going on with your network.