[1]http://michael-coates.blogspot.com/2013/09/security-capabili...
Why not? For browsers that don't support HSTS, the header will be ignored. For those that do support it, the end-user gets better security. Is there a feasible reason for not enabling it everywhere? My guess would be so Facebook can disable SSL for certain browsers?
Btw. There are many sites like this out there. So this isn't news actually. There are even more sites which lack https completely.