We don't have any plans for implementing SSL that I am aware of.
Yes, you're sending your login info in the clear at the moment. Because of that, I would recommend that you use a password here that you don't use elsewhere, and then there shouldn't really be an issue.
-Tim



