> if you visit wikipedia.org/whistleblowing
Just visiting, sure but if you edit it to leak a secret the protection is everything.
Say you are on your school network and leak something damaging about the school on Wikipedia.
Prior to Wikpedia switching to HTTPS, both the school and any intermediate network could see
- you visited Wikipedia
- you edited Wikipedia
- what you wrote on Wikipedia
After HTTPS, your school could see - you visited Wikipedia
That's strictly better in every way.
> if you edit it to leak a secret the protection is everything.
It’s really not, because knowing when you edited it is already enough, given that there’s a timestamped edit history. And the size and shape of your request payloads will show that you edited it, not merely performed GET requests.