SSL documentation in most major projects still needs a lot of polishing.
I also think there needs to be a push to separate the encryption and remote server verification parts of SSL/TLS. I'd love to encrypt all communication with the sites I run, but am completely uninterested in coughing up cash for an SSL cert.
As they should. Since there is no way to verify the remote server then the connection is vulnerable to man-in-the-middle attacks. In that situation an attacker can simply pretend to be the server and decrypt your traffic.
I also think there needs to be a push to separate the encryption and remote server verification parts of SSL/TLS. I'd love to encrypt all communication with the sites I run, but am completely uninterested in coughing up cash for an SSL cert.