That way active attackers cannot spoof download links for software from insecure pages and credentials cannot be leaked passively from the forums. https://wiki.whatwg.org/wiki/TLS has more reasons if those are not sufficient. Endgame: http://hstspreload.appspot.com/