>I mean that HTTP/2 must be secure against (at least) passive 
>eavesdropping attacks at all times. 

Pardon me for being a bit blunt:   You and what army ?

I can understand if you insist that _your_ website can always
be protected if you desire that.

But I utterly fail to see what mandate you have to insist that some
random 3rd party must protect their website at all times, countrary
to their own wishes, and in particular when they may be legally
prevented from doing so by applicable regulations.

