5.1 Security Considerations for Implementers

Forms based authentication necessarily transmits the user’s identity as plain text. Implementers are encouraged to use a secure channel, such as HTTPS, to avoid inadvertently exposing the user’s identity.