Bad security should be marked as bad. No security is not inherently bad.
Bad security should be marked as bad. No security is not inherently bad.
A real but milder story - a customer of mine once complained about the advertising on my website being slightly offensive. I didn't have any advertising. When I investigated, it turned out the advertising was being injected by malware on his own computer. Not that HTTPS would have solved that, but I've heard of ISPs doing similar things where it would be prevented.
I'm guessing you think your church website isn't worth securing because it doesn't have any sensitive content. But in a world where surveillance is pervasive, that's not something you should depend on. For example, if religious discrimination were to lead to members of your church being harassed because of their viewing habits, then the argument that the content isn't sensitive doesn't seem so strong anymore.
HTTPS doesn't hide the IP or even the hostname (SNI is sent in cleartext) of the site you're connecting to, nor the IP of the client, so it'd still be trivial to determine who is visiting the church's website - just not exactly what pages on the site they've viewed. You need something more like Tor or stronger to protect against that.
Most tracking of people is done by advertising, and marketing companies. Should we mark all websites with advertising as insecure?
On the other hand, using HTTP would open an otherwise harmless content provider to potential ad-insertion attacks by third parties. So in that sense, HTTPS really does matter here.
And no security isn't inherently bad, but a browser warning doesn't have to be judgmental, it just has to be informative. Warning for a bad cert or a self-signed cert but not displaying any warning for an unsecured connection is misleading, as it implies an unsecured connection is more secure than a self signed cert. By warning in some cases the browser has taken responsibility for providing information about connection security, it should do the best job it can at that, and that should mean warning users that unsecured connections are unsecured.