That's fair enough. However, this does not preclude you from presenting the log-in form over a secure connection and processing the form information over HTTPS, followed by redirection back to HTTP.
P.S. The main page looks really bad when HTTPS is enforced.