Type xkcd.com
in location bar, hit return -> https://xkcd.com
.
But if I type http://xkcd.com
instead, it does not change to HTTPS.
I've checked both URLs, and they're not using HSTS headers. I'm not using HTTPS Everywhere. (And in either case, I wouldn't have expected it to be so easily bypassed). I don't have the HTTPS site bookmarked - in fact I have the HTTP url bookmarked.
Iceweasel (Firefox-ish) 16.0.2. (I guess my updates are probably slightly screwed up).
How does this work? Do other browsers do it as well?