If it's enforced server-side, then there's still an initial connection that is unsecured and can potentially be intercepted/modified before it gets to the redirect from 80 to 443.
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments