Hi,
I looked at some topics stating that login is done via HTTPS, but... is that only through the main website? When I access my blog and try to log in the form still points to the same login script (wp-login.php) but over HTTP (not HTTPS). This is obviously a certificate thing (issued for http://www.wordpress.com only) but I think it should be more clear for users when their password is in plain text and when it is not...
Cheers,
Maciej