Earlier quoted context omitted.
In the original Dutch article ( https://decorrespondent.nl/845/Dit-geef-je-allemaal-prijs-al... ) the author explained in the comments that they used SSLstrip for facebook and live.com So, the connection was over HTTP and not HTTPS. They added a padlock favicon.ico image to give the impression the site was secure
Ah. I wonder how hard would it be to extend protocol to let Facebook, for example, state that they will never go https again, so that browser would scream.
http://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security