I believe it reduces MITM attack surface because initial connection request which comes before the HTTP-to-HTTPS redirect is bypassed by the browser itself - goes straight for HTTPS out of the gate. Or something like that... I'm just a hobbyist computer geek