While being connected on a very restricted network, I was only able to access the internet through a Squid proxy which was configured only for HTTP on port 80.
When navigating to google.com, I'm able to receive the site yet with no SSL on. I checked the HSTS record for google.com at chrome://net-internals/hsts and records exists.
So how come the site is still loading in browser and downgraded to http/80? It's the same as an MITM attack... I thought HSTS would block this.