They are insecure, because your ISP can change website responses and text format doesn't protect from that. So basically browser can't guarantee that you're looking at original web server response.
Insecure only if HTTP instead of HTTPS.
The format being text, html, video, or an executable program has nothing to do with it.
With checksum & sign nothing can be guaranteed, right ?
Insecure only if HTTP instead of HTTPS.
The format being text, html, video, or an executable program has nothing to do with it.