It looks like the forum login isn't properly secured (http instead of https). Please investigate and fix on a priority basis so as to not compromise any user accounts. Kudos to @texwood for discovering this.
I've just tested. Signed out of community, closed and restarted my browser, signed back in manually. Before pressing sign in, verified address bar showed https. Successful login. Still shows https.
I know this may not be for the average joe user, but if you add a "s" to the http so that it becomes "https:" with the existing URL, it will actually change it to secure.
But +1 to this idea definitely for those who aren't technologically savvy. Would probably be an easy fix of redoing the hyperlinks on the main site.
This http/https thing is all over the map. The problem with manually adding s is that it doesn't stick. The links seem to default to http. I tried to change the link to this thread to https and it worked. When I click on the community forum link on the top right from within this thread, I go right back to http and stay on http. The default should be https universally.