I second this. Their market share affords them far too much luxury with not nearly enough impartial oversight.
> I dont understand why they are doing this.
I do understand why they're doing this. Me and you are smart enough to know to only trust a download from a secure connection. Others don't. I've fixed two computers THIS MONTH from people who opened email attachments and then proceeded to click past all of the Office security warnings. Both of them were Kovter droppers. The average user doesn't know what the padlock means, and if you hid a non secure download behind an https redirect they wouldn't even know.
Another story, just last week, my town of 9k people has a "social network" based on dotNetNuke on some sketchy shared/co-hosted server without HTTPS. They tried to spam their network on a local FB group recently and they don't even have an SSL cert. Still, the sheer volume of idiots who visited and posted comments like "there's a bug, I can't create an account" or "just signed up!" was disgusting. I posted a stark warning and chewed out the spammer for not taking the 10 minutes to get a free SSL cert, which was when I learned of their sketchy hosting situation.
So you see, not only do regular users not know what their looking at on the internet; other web developers also have no idea and don't really care. They insisted to me they have their own security measures which negate the liablity of not encrypting traffic; to which I responded that I could setup a fake AP at the local coffee shop and start stealing passwords if he didn't beleive me. The post was deleted after that, but most of the country bumpkins in my town stood BEHIND HIM!!! They thought I was being mean to a local business.
The boogey-man can't sneak up on us, but many people are just going through life and need someone to watch their back digitally. Besides, the only time you initiate a non-secure download of an application from a secure connection is when you've injected payload fetching code into an XSS vulnerability. I can see literally no other use-case unless the developer is an idiot (see paragraph 3).