@angristan @vurpo I’m also not convinced yet. It’s not super expensive to run a HTTPS site and even small mirrors can afford the certificate thanks to Let’s Encrypt. The extra server load for encryption is minor as well.
When I check for lists of Gentoo mirrors there are dozens of mirrors listed that support HTTPS, so it can’t be a big issue that “Debian and Ubuntu needs to talk to them” 🙄