Perhaps a better insight is looking at parties doing TLS termination globally as a reverse proxy service, for example for DDoS mitigation or acting as a web application firewall. Or, who handles your (encrypted) DNS requests? A somewhat trustworthy local ISP, or a large corporation with multiple pages of terms of service and a vague privacy statement? (I'm unfortunately also aware that there exist ISPs that inject ads on non-encrypted connections, or having done so in the past)
In my opinion, it's less about the amount of cleartext traffic, but also about what parties terminate your so preciously encrypted connections/requests, the percentage of internet traffic they handle, and what they exactly store about those requests.
Encryption on the internet doesn't mean it's suddenly safe.
Comments
Perhaps a better insight is looking at parties doing TLS termination globally as a reverse proxy service, for example for DDoS mitigation or acting as a web application firewall. Or, who handles your (encrypted) DNS requests? A somewhat trustworthy local ISP, or a large corporation with multiple pages of terms of service and a vague privacy statement? (I'm unfortunately also aware that there exist ISPs that inject ads on non-encrypted connections, or having done so in the past)
In my opinion, it's less about the amount of cleartext traffic, but also about what parties terminate your so preciously encrypted connections/requests, the percentage of internet traffic they handle, and what they exactly store about those requests.
Encryption on the internet doesn't mean it's suddenly safe.