If end-to-end sec (e.g., crypto signatures) are used, like say with Debian packages which uses GPG, packages and metadata can be released over http without a problem.
Also, openssl didn't (or doesn't) appear to care about high-reliability software engineering and the IETF TLS Working Group didn't care about producing a minimum-featured spec that is not overly difficult to implement, maintain and support in the real world. Instead, TLS has become a kitchen-sink, feature-hoarding, experiment-in-production jambalaya.
It's hard to tell from the paper, because they don't include either specific build version numbers of browsers / servers nor date of publication, so their results are difficult (e.g., impossible) to reproduce exactly.