Why doesn't it auto-redirect? (Not a criticism, just curiosity.)
You should see SSL from Google though.
Sure. An unconditional redirect would be better, but that requires a dedicated IP
Neat idea, but wouldn't this still be exposed to ISP-level attacks? Since the user is still loading the page initially in plain HTTP, so the ISP could still inject code, remove the JS redirect, etc.