"We're working on those ....google.com is complicated"
Having a top rank in Google results is a very serious business for a lot of companies. If this trend continues for HSTS i am a little worried.
I do understand Google likes to encourage the rest of the world to have an as secure possible internet infrastructure, but i'm not so sure if those same companies would accept a lower Google ranking just because their IT department will tell them "It's complicated".
It's not evil by far. But it's not really nice as well.
By the way. Just checked https://hstspreload.org/?domain=blog.google. It says No HSTS header is present on the response.
As for blog.google, that's the beauty of TLD-wide HSTS. You don't need to do anything special on the individual websites, such as configuring headers, to get the benefit of HSTS. All you have to do is set up an SSL cert.
The hstspreload.org site does not yet correctly display results for when a parent has HSTS enabled, but your browser itself does do the right thing. As for fixing what hstspreload.org displays, that's something I might take a crack at: https://github.com/chromium/hstspreload/issues/85
I’m curious as to why the www. version was made the default after some time? Would you happen to know the story behind it?
What other than http://clients1.google.com/generate_204 needs that?
(And yeah, that should always have been on a separate domain entirely, but, hindsight.)