Support for HTTP-01 Challenge over Port 443 with Self-Signed Certificate (for Port 80-Blocked Environments)

I still don't see how using https is any less secure than http - the web server is responsible for using the right server {} block based on SNI - what am I missing?