Google May Push Sites to Use Encryption
blogs.wsj.com
blogs.wsj.com
However, for static content only sites, what is the point?
1) It effectively ends the ability to run passive mass-eavesdropping devices. Even without checked authenticity, you still force anybody trying to listen in to run a more expensive (in both money and CPU) MitM attack. Changing costs from "deploy once and record everybody" to "pay per-target" is huge.
2) We need to normalize (socially) the use of encryption in general, so the people that DO need it don't look suspicious. To paraphrase Phil Zimmermann[1], what you're sending may be simply a holiday greeting-card, but you still put it in an envelope.
[1] http://www.philzimmermann.com/EN/essays/WhyIWrotePGP.html
For anyone who wants more than 3 then they have to pay a fee.