I have been looking into setting up SSL for my blog. There currently no free way to get SSL certificates. There are some free ones but they tend to come with strings and lure you into paid plans. I am not sure if this proposal is the best.
What needs to change, in addition to this, is the interstitial warning page for a self-signed certificate needs to go away.
Having a self-signed cert > http.
It really depends on what exactly you are talking about. For a Man-in-the-middle attack, your statement is false. For passive dragnet surveillance, your statement is true.
I think people underestimate MITM attacks...
Not with certificate pinning.
overall assessment: >