However besides that...just curious: Will Chrome honor a header to disable HSTS for preloaded domains? (e.g. Strict-Transport-Security: max-age=0)? And what is going to happen if I submit my .dev site for removal from https://hstspreload.org/ ?
Also, reading the rules on hstspreload.org, I see the following statement: "Don't request inclusion unless you're sure that you can support HTTPS for your entire site and all its subdomains the long term"
Since you cannot actually guarantee that every .dev site will support HTTPS considering the fact that many developers use it on their LAN...don't you think you're breaking the rules here and possibly causing more problems than solutions?