Insecure? Bullshit. They should remove http then. I'd respect them if they just said they're lazy and don't want to support the ftp protocol.
They're working on it. It has and will continue to be deprecated with ever increasing security warnings.
But the reason why FTP got pulled and HTTP hasn't is simply usage. The FTP client in browsers is terrible, and anyone using FTP professionally is using a better client (e.g. multiple connection modes, resume downloads, concurrent streams, etc) or has already migrated to FTPS or SFTP.
FTP just adds attack surface and maintenance cost.