Few sources that claim that TSL is almost free today.
https://www.imperialviolet.org/2010/06/25/overclocking-ssl.h...
https://istlsfastyet.com/
http://blog.codinghorror.com/should-all-web-traffic-be-encry...
Although you may argue that if you are a CDN, encryption can be a significant portion of your costs.
Also, Jeff Atwood writes following:
> Of course, there's no reason to encrypt traffic for anonymous, not-logged-in users, and Twitter doesn't. You get a plain old HTTP connection until you log in, at which point they automatically switch to HTTPS encryption. Makes sense.
Today we know that it is no longer a valid point. TOR users can be deanonimized by injecting traffic into plain HTTP connections. Upgrade to HTTPS seems to be fixing that. So we really should use HTTPS by default and HTTP only in very well articulated cases.