Unbelievable. Banks, of all entities, having unsecure logins. If the browser lock is missing on your bank’s login page your login information is not secure. SSL, the security part of a login page, encrypts the user name and password -and- makes sure you are talking to your bank and not some other site. So if your bank’s login page shows http:// it is not secure and there is no (SSL) guarantee that you are actually on the bank’s login page - it could be a spoofed login page.
Yes, banks will say your login information is secure but if the lock and https:// is missing then it is not. Period. Note that some banks do have secure login forms but they are not the default. You have to hunt for them.
Here is a list of offending banks
Doug