The sentiment is there, but there's just so much wrong in this article, I can't believe it. Beginning with the fact that HTTPS certs DO provide security, exactly in the cases the author dismisses: someone who man-in-the-middles the connection, at any point between the server and the client, can't tamper with the HTTPS connection undetectably. It either requires a compromised server or domain (so you can sign the tampered content), or a compromised client, to accept a tampered content.