the java server pages application that serves the main site has extended validation https://www.symantec.com/index.jsp
but connect doesn't. It seems like https://www.symantec.com/connect/ redirects to http://www.symantec.com/connect/
r.port="https"===o[0]?"443":"80"
Why can't Symantec afford to put ssl on its connect site? It is not like they have to pay anyone for a certificate...