> First of all encryption cannot stand on it's own, it needs the concept of trust.
Wrong. Passive eavesdroppers. Pay attention.
> There is another cost and that's the actual cost in CPU cycles. SSL is bloody expensive compared to not doing it.
Wrong. AES-NI and the fact that Google uses it should be proof enough. This used to be true, but isn't anymore.
> Until fairly recently there was no real way to scale SSL without handing over your private keys to a your frontend SSL machines.
I'm pretty sure Cloudflare did not invent this.
> forcing SSL on people out of principle should consider that
I'm sorry I don't hate freedom like you.
> A big cost of encryption however is lawful interception.
If this is your problem then just give them the keys. Problem solved.
> [antivirus] started to destroy SSL traffic
I would assume that the MITM proxy running on localhost also checks CAs, so what's the problem? (besides breaking cert pinning)
> I'm firmly of the opinion that none of [SSL MITM] would have happened if SSL traffic was less common.
OF COURSE not. They would just MITM it without crypto stuff. So… it would just be worse.
> There will be the point in a year or two when the first websites that got forgotten and had SSL configured
What's so special about a year or two from now?