Is there any reason why I would want to use https for this use case?
Or what does "entire web" mean?
Is there any reason why I would want to use https for this use case?
Or what does "entire web" mean?
If you use HTTPS you prevent alterations to that traffic and people receive exactly what you expect they should receive.
Examples of recent ISP misbehaving on non-https websites just 25 days ago on HN: https://news.ycombinator.com/item?id=8500131
Note that the Verizon issue isn't anything entirely content altering but someone who lives in a country with strict monitoring of traffic could easily change the wording of your website to match their propaganda if you aren't using HTTPS.
So yes, your content is publicly available free stuff and no one is probably sending you user login credentials or credit cards but it still matters.
Over http it could conceivably have malicious or tracking content introduced without your knowledge.
Yes it can help you stop:
ISPs inserting adverts into your content (this has happened)
Governments censoring your content or rewriting it
Governments putting people in jail for reading your publicly available (in your country) content, which is illegal in theirs
People impersonating your website
But if you don't want to use it, that's cool too. I suspect all websites will be encrypted at some point soon though, the disadvantages are getting less and less important.
How does that work, surely the gov can still see people accessing the information by monitoring network traffic and the info itself is still public. HTTPS doesn't encrypt the actual request traffic does it, and in any case the gov would still see which server the traffic is going to unless you're using something like tor [and possibly still then].
"User X browses Wikipedia"
and
"User X browses Wikipedia articles about topics A, B, C"
where topics A, B, C could be anything user X doesn't want people recording them reading about: for instance, various political articles, articles about mental illness, articles about LGBT issues, etc. Fill in the blanks.
One interesting idea I heard from someone recently is tuning compression so that you target a small number of total page sizes -- rather than padding to expand pages to the same sizes, just don't compress them all quite as well as you could have.
Both GnuTLS[1] and Nginx[2] have length hiding implemented. But AFAIK OpenSSL doesn't have it yet, so most users are still left in the dark.
[1]http://www.manpagez.com/info/gnutls/gnutls-3.2.10/gnutls_180...
It might still be challenging to get large sides to adopt padding that will increase the amount of traffic they send (of course, the idea of reducing the efficiency of compression has the same net effect). But it's great to know that there's already a tool in place for traffic padding, at least in some implementations.
However, you can figure out what pages on a large public site like Wikipedia people are reading over HTTPS, based on statistical traffic analysis, because you can see the size of the request, page, and each of the images. Combined with link following analysis, you can make a fairly accurate guess as to what people are reading.
HTTPS will also make an attacker unable to change your content.
Like you, I don't host any private or remotely sensitive information. I'm encrypting my site because I think it's the right thing to do, even though there's little personal return on investment.