@jessew @Stellar it’s not just forced TLS, it’s HSTS, also known as CRINGE
The standard says that if the cert is invalid (like if it has expired because the website operator is an eepy princess) a conforming user-agent must strip the user of their ability to bypass the security warning and go to the site anyway. And browsers do implement this and i HATE IT!! TOTAL HSTS DEATH