Public key pinning coming in Chrome 13
imperialviolet.org
imperialviolet.org
The malware could just as well intercept your data before it is encrypted, for example, by installing a rogue SSL library. No need for sniffing and fake certs.
If you're infected with malware, just patch Chrome in memory to report everything as SSL connected, etc. If you're already compromised, nothing Google can do can help you.
The purpose of STS is to avoid the user accidentally going to the http address of a page instead of the https page. This is achieved by a special HTTP header that is sent from the server to the browser. The browser remembers that the server wishes to be contacted only over https, and from that moment on all network traffic from the browser to that domain will only be possible over https. No way for the user to accidentally type http://gmail.com/.
How is this different from a 302 location redirect header from the http:// url to the https:// url?
Also, redirecting from e.g. http://gmail.com/login?user=me&pass=secret to https://gmail.com/login?user=me&pass=secret is not that useful, so this can also help with some forms.