So I noticed that the front page is not encrypted. I thought for a while that this meant that the login process was not encrypted either until I saw this line in the front page source:
This is nice, but it would be even nicer if you made the front page encrypted as well. It would prove the website's identity and assure us quickly that we are not being phished.