Websites can automatically redirect to HTTPS if the client connects on http, but many websites don't redirect
You could create a separate "secure" profile and feel safe that all traffic is secured, while still being able to browse HTTP in another profile, for instance.