2) Some banks have login forms on un-encrypted pages
I've not seen a bank do it, but these guys do, which I think is just insane, especially seeing as in all other respects (apart from price) they are an excellent domain registrar. Click the login link in the top left and you'll be presented with a non-https page with a username and password on it. I've emailed them about it but they just don't get it. Idiots.
I've stopped using MelbourneIT for new registrations on that basis. I suggest you do the same.
If you check the login form's source you'll notice that it is being submitted to an https URL.
I've stopped using MelbourneIT for new registrations on that basis. I suggest you do the same.
If you check the login form's source you'll notice that it is being submitted to an https URL.