Actually, since it's a login/persistant cookie sort of authentication deal, it's not all that rough. I never really thought about the security of FR before because I never think in terms of doing her harm, but there are likely a lot of reasonably easy dodges around this model to get in behind the scenes. Maybe. Depends how much of his homework JohnRob did.
Even sniffing for passwords is (somewhat) reasonable on the http: non secure model we are presently on! Certs are obviously the way to go to prevent all that treachery.
I cannot be open about the Fed measures in place, for obvious reasons, but it is a very fascinating and pretty durned rugged setup they've got.
If we just had our own geosync internet communication satellite.