From private correspondence with Ben Kelly:
"A user recently reported that they are able to do the following:
1) We set up a secure domain test.com, and installed a service worker on it.
2) We set up an insecure page on http://test-insecure.com that opened an iframe to https://test.com - let's call that the "secure iframe". We found that while a script in the secure iframe could also not access getRegistration, any fetches it makes are intercepted by the service worker on test.com. That gives us a way to talk to an existing service worker from an insecure page."
The user reported this applies to Chrome as well as Firefox.
Comment 1 by benl...@mobify.me
, Apr 28 2016