It has SSL on the main domain, and some subdomains without SSL (wildcard perhaps?). The main domain (when accessed over SSL?) redirects to a subdomain with plain HTTP.
Kinda weird setup!
Edit: okay, the subdomains also have SSL. I guess the random subdomain thing is to make sure it hasn’t been cached in a “this site has HTTPS” list. The HTTPS is needed, of course, to please the browser makers, as the parent says.