HN is already set up for SSL; the changeover happened around two months ago[1].
If your concern is that you should be forced to the HTTPS site, even if you mistype or bookmark the wrong version, etc., then you could try the EFF's HTTPS-Everywhere extension (Firefox only. I'm told Chrome's extension framework is fundamentally incompatible right now).[2] If you've noticed a lot of comments have linked to, for example, Wikipedia using a "secure.wikimedia.org/wikipedia" type URL, this extension is very likely how they got that way.
Out of the box, there is no ruleset preconfigured in HTTPS-Everywhere for HN, but the top comment[3] on the HN SSL announcement/discovery post gives a rule for it to configure it to always force HN to SSL.
Ah, thanks. I missed that, and haven't checked in 2 months.
I actually have HTTPS Everywhere, but it didn't find it for the reasons you mention.
If anyone at HN is reading, the certificate doesn't work if you visit via news.ycombinator.org (vs .com). It would probably be better to just make that a redirect to .com, rather than what appears to be an alias.
there is also the HTTPS Finder[1] add-on that automatically discovers HTTPS versions of webpages, and offers to generate HTTPS-Everywhere rules for them.