It would be reassuring to users if the connection for the sign-in process was encrypted. In many cases, this would require generating self-signed certificates that would trigger the browser\'s loud warnings about possible forgeries and insecure connections, so it should be an optional feature at most. It should be possible for sites that already have legitimate SSL certs to use them, however.