That's not a downgrade, but a lack of upgrade. A few comments back said https://evil but it would have to instead be http://evil assuming no rogue root cert is installed.
And requires that if the user had visited chase.com, that chase.com not have includeSubdomains in their HSTS header.