Seriously! It's 2016, unless you rely on 3rd party resources that don't support HTTPS there's no reason why your site shouldn't be HTTPS only. Certificates are free and there's negligible performance overhead with modern CPUs.
Yes, but that's not a general MITM attack as the NSA has pulled off. Only the folks at that particular coffee shop are placed at risk from this particular adversary.