I hope you are aware that modern malware is very capable of spying on the OS level, not only network traffic where it makes no difference whatsoever what protocol you are using between your server and the clients browser. In other words, securing over HTTPS for what must be 99.99% public information vs 0.01% private messages makes it a big waste of resources to the point I'd call it overkill. The chance that someone is interested in what people post here is close to zero in reality - if anything, the likelyhood of your server / forum-software being hacked (and private content being read) is proportionally a lot higher - either by bruteforce based attacks directed at individual member or admin accounts - or by exploit based attacks directed directly at your software. In these cases, HTTPS matters absolutely zero. The likelyhood of HTTPS being a factor in securing login details and the little amount of private messages (relative to the rest of the content that is being created) is a very small fraction.
But sure, in the paranoid world we live in with the NSA & KGB with their supercomputers and teenage l33t hackers and their cousins breathing down our necks and interested in every single individuals public tweets or their view on gaming; lets crank up TLS/SSL with at least 65536bit encyrption (so that no one in at least a billion years will ever be able to decypher it, not withstanding that everyones browser will take 30 minutes to load each click) so that everyone can feel safe & secure...
But sure, in the paranoid world we live in with the NSA & KGB with their supercomputers and teenage l33t hackers and their cousins breathing down our necks and interested in every single individuals public tweets or their view on gaming; lets crank up TLS/SSL with at least 65536bit encyrption (so that no one in at least a billion years will ever be able to decypher it, not withstanding that everyones browser will take 30 minutes to load each click) so that everyone can feel safe & secure...