>>14
I agree that authinfo should be sent over a secure channel.
BUT I am not logged in, will not login, and never intend to.
Thus everything on that page is publicly available.
(Why they don't make cookies IP-dependent most of the time is odd. With that, even if someone has the cookie, they'll need to figure out your IP, and then figure out a way to spoof it while being able to communicate. Unless the attacker happens to reside on the same subnet as you, very difficult.)