[1]: https://github.com/EFForg/https-everywhere/tree/master/src/c...
What if it's their bank and they really need to pay a bill right now? Maybe the HTTPS site is just broken right now.
Users aren't wrong for clicking yes through these dialogs. This kind of UX is setting them up for failure with impossible choices. Its even worse in practice: users (including programmers, as evidenced by the comments in every HN thread about HTTPS) won't understand everything that's in play before making this decision. Assume users always click yes.
HSTS, preloading and restricting new features to HTTPS etc. are ultimately working to deprecate non-HTTP (inside browsers).
> "Maybe the HTTPS site is just broken right now."
In the case of a bank, it's extremely unlikely that they are falling back to HTTP. It's much more likely that sslstrip is in place if you had this. The cost and hassle of someone having access to your whole bank account, is likely much higher than the fines for a late payment.
You'll also be going against specs, HTTP should go to port 80( which typically isn't secure.), a browser unilaterally deciding to go against a legitimate user wish is bad form.
Any site lacking HTTPS should instantly close connection attempts on port 443. But some it seems choose not to respond at all, making the browser unsure if the site is just slow or if an HTTPS service doesn't exist.
Besides, now that most sites run on https, making the http-only ones slower would be a good thing.
When it comes to security, TLS is crucial to the security infrastructure of the internet as a whole; however most of the current security problems on the internet don't actually involve TLS vulnerabilities, even though those tend to make a lot of news in the technology press.
The bar for exploiting TLS vulnerabilities generally requires setting up a legitimate seeming entity and injecting yourself into the internet traffic routing infrastructure, it is very much possibly (and indeed easy for state actors) but it is a much higher bar for common cyber criminals.
Currently site owners are not allowed to default into https on first visit. Trying both will give them this choice.