HSTS is a crappy hack introduced because the industry has never had a sunset plan for protocols. When you do Enterprise engineering, you are aware that nearly every single project will die, and so you start the project by planning for how you will kill it in such a way that people can migrate to a new thing as painlessly as possible. But the industry doesn't do that with protocols. So they can't ever die. Because of that, we need backwards compatibility forever and there's extremely little innovation in widely adopted solutions. So any new "fix" has to come as an optional band-aid that falls off if you look at it sideways.
HSTS is the band-aid used to continue propping up our lack of ability to kill off HTTP. Quite simply, HTTPS just doesn't work everywhere. That's why HSTS exists - because we can't just tell browsers "stop supporting unencrypted HTTP". And rather than try to find a way to kill HTTP, or change HTTPS to provide for the things HTTP does, instead we have this optional flag that tells the browser how to manage two things: 1) the site's certs, and 2) browser behavior around a subdomain.
Why do I say it's not security? Because there's plenty of ways around it. Because not all clients support it. Because a server has to explicitly enable it, and do it correctly, which this article shows isn't happening even for the biggest websites. And because if your website isn't in this special preload list, you don't get the benefits of it anyway. (Why the fuck do we have PKI based on the integrity of 350 different CAs if it's meaningless without bundling your individual domain's special configuration with the browser?)
Real security isn't something you can just turn off or avoid. It doesn't require you to submit every domain you want to be secured to a special list packaged in the browser.