It's called bad design, not really a bug (unless you've seen the specs for it and they say otherwise). It's been there forever too. It is also using https when the data is sent...so there should be an encrypted connection when the data is sent (hopefully).