At this time, the server repos.fedorapeople.org doesn't listen on port 443.
Binary software is hosted on that server, often packages aren't signed by a Fedora key (if they are signed at all), and some providers of packages might suggest to disable gpg signature checking.
We should make it difficult for MITMs to transparently provide manipulated binaries while they are being downloaded.
I suggest to enable the server repos.fedorapeople.org to support httpS (this ticket).
(Once that's done, we should encourage all people to use https in the URL parameters they provide as part of their repository configuration. Maybe plain http can be discouraged at a future time.)
Just as an update here:
I think this is a fine idea and we should do it.
We are waiting on getting a ssl cert before we can enable things.
As soon as we have the cert we will get it enabled.
This is now live.
All links to fedorapeople.org should use the new wildcard cert there and https.
Please file a new ticket if you see any that are not...