Their unencrypted pricing page links to that encrypted order form page. We all agree there should be no http to http transitions like that, right?
If you'll note, that encrypted order page is on the same host as their unencrypted pages. Both rsync.net and www.rsync.net covered by the cert. They have SSL set up already, and they just purposely redirect away to http for their static pages. That is a well-known ssl antipattern.