I'd really like to know which of these is the better solution.
It seems to me that if people go to the http address, they could be redirected to an attacker's address with a simple MITM attack. So there's an argument to be made for not using http at all, even for a legitimate redirect, because it can be so easily MITM'ed.
On the other hand, if the http address is left unused, then people who try it anyway and it fails will be confused. For this solution to work, it seems the users have to be educated to always and only use the https address.
For these reasons, the whole separate http/https scheme seems broken by design.
What's the consensus from the security community as to the right setup here? Am I missing something, or is there a better way?