Re: Avoid HTTPS when possible?

After the recent CA desasters, I wonder if one should avoid HTTPS
whenever possible, in order not to create a false sense of

Another problem is that browsers tend to force-feed CAs, even infamous ones such as CNNIC, on users. Removing a CA can be complicated for end users, and removed CAs may be automatically and silently re-added when the browser software is updated.

Thor Kottelin