Why doesn't Steam use encrypted connections?

Because deploying ssl for a single site is much, much easier then deploying ssl for something like steam.

They have multiple servers and endpoints, which means they would need to make sure everyone sending data to those endpoints are also on ssl. Https does not play nicely with http content. Not to mention all the user linked stuff, such as game screen shots on store pages and community content which gets linked from random sites.

All the critical pages are already secured anyways, Steamworks is secure. The checkout page is secure. The only place that isn't ssl'd seems to be the storefront, and I challenge you to give me a good reason why it would need to be.

/r/Steam Thread Parent