Yes, payments, logins, and password changes are done over HTTPS, for instance. (Logging in on a non-HTTPS page, such as through the navigation strip, is done with in-browser encryption.)
We do keep meaning to add "always-HTTPS" mode, even if only as a paid feature (because of load), but there's a lot of yak-shaving that has to be done first. It's on the list, though.
no subject
Yes, payments, logins, and password changes are done over HTTPS, for instance. (Logging in on a non-HTTPS page, such as through the navigation strip, is done with in-browser encryption.)
We do keep meaning to add "always-HTTPS" mode, even if only as a paid feature (because of load), but there's a lot of yak-shaving that has to be done first. It's on the list, though.