If baidu.com is distributing the script, why is baidu.com not being flagged as malware by the various mechanisms used to block this kind of nastiness?
Are the vendors just cowards?
Are the vendors just cowards?
One reason may be that http makes it easier for surveillance or injection.
I don't know if what's the reasoning behind that.
If you ever manage to load that CDN over HTTPS/QUIC it sets a HSTS header so all further pageloads will go over HTTPS.