> A better solution is to make TLS cheap to setup. Really, really cheap -
> because it's not.

It's pretty close to as easy and cheap as it can be:

(And, read all the way to the end for the sad story of why my blog is HTTP)

It's not as easy as it is for SSH, for sure — but that is because the
problem web PKI has to solve is a lot harder: you have to introduce
many more clients to the server.

