Re: It failed utterly with my browser
Slightly exaggerated, not inaccurate. Just like post-9/11 airport security, HTTPS isn't completely useless as a defense/deterrent. I just switched another site over to HTTPS yesterday. It'll make the backend slightly harder to hack, and the cost was relatively low, but the *appearance of safety* was the main driver.
Serious web security improvements are only possible by rebuilding these sites, purging the fad crap (CMS, web 2.0, social, analytics, 3rd-party JS), not collecting user info... generally reducing the attack surface, exploit value, and complexity. HTTPS isn't part of that, it's just a band-aid.