While I'm not opposed to providing via HTTPS, I don't think
it's as simple as "let's just do it!".  Who will be responsible for making
sure the cert is up to date?  Who will pay for certs (if we don't go with

Also, forcing all traffic to HTTPS unnecessarily complicates some things,
e.g. screen scrapers (and before you say, "well, screen scraping sucks,
anyway!", I think it's not a stretch to say that "microdata parser" falls
under "screen scraping".  Or RDFa.). I feel a little uncomfortable with
adding the overhead HTTPS brings wholesale, when there are tools (like you
mention, HTTPS Everywhere) for those that want HTTPS.  It feels a little
like the xkcd "server attention span" comic to me [0].



> NSA broke it already
> On Mon, Nov 4, 2013 at 1:42 PM, William Denton wrote:
> > I think it's time we made everything on use HTTPS by
> default
> > and redirect people to HTTPS from HTTP when needed.  (Right now there's
> an
> > outdated self-signed SSL certificate on the site, so someone took a stab
> at
> > this earlier, but it's time to do it right.)
> > them for prices that seem to run over $100 per year (which seems
> ridiculous
> > to me, but maybe there's a good reason).
> > More broadly, I think everyone should be using HTTPS everywhere (and
> > Everywhere, the browser extension).  Are any of you implementing HTTPS on
> > your institution's sites, and moving to it as default?  It's one of those
> > slightly finicky things that on the surface isn't necessary (why bother
> > with a library's opening hours or address?) but deeper down is, because
> > everyone should be able to browse the web without being monitored.
