We should switch to HTTPS by default, maybe by integrating LetsEncrypt / [auto-sni](https://github.com/DylanPiercey/auto-sni) or at least a dummy certificate for development.