As a matter of fact, in Korea, every e-commerce site is required by law to use TLS. Even if you don't sell anything online, you must use TLS if you're for-profit and you have any sort of login system. It's been the law since last August. CAs have been making a lot of money lately.
That's interesting. As an American programmer, it seems obvious to me that merchants and credit card providers would find it in their interests to prevent fraud and credit card theft. Do you have any insight in to why Koreans feel differently about that? Is there something different about the legal system that makes civil liability for unauthorized card use an insufficient motivation to use reasonable security measures?
The potential liability for not encrypting usernames and passwords is probably negligible compared to the liability for not encrypting payment details. So in the absence of government regulation, there's not enough financial incentive for merchants to encrypt non-money-related stuff.