Or at the bare minimum, secure the login so password details aren't sent as plain text over an unsecured channel