> This forcing of opinionated things goes on my nerves. How about develop the browser, and let the mass decide what they use.
It's Google's browser forcing one of Google's own gTLDs to HTTPS. There is no masses involved. Anything else on the HSTS preload list is there at the request of the domain or gTLD owners.
> Amazon was 100% HTTP for 20 years (except the single login page) - it worked very well.
Sure it did! It also allowed any interested party to observe all your interactions with Amazon. What worked 20 years ago doesn't necessarily work today. Standards evolve, new attack vectors emerge, and people's needs for privacy or what they expect to be private changes.
It's Google's browser forcing one of Google's own gTLDs to HTTPS. There is no masses involved. Anything else on the HSTS preload list is there at the request of the domain or gTLD owners.
> Amazon was 100% HTTP for 20 years (except the single login page) - it worked very well.
Sure it did! It also allowed any interested party to observe all your interactions with Amazon. What worked 20 years ago doesn't necessarily work today. Standards evolve, new attack vectors emerge, and people's needs for privacy or what they expect to be private changes.