Hi all,
With all the talk about turning on $wgSecureLogin for WMF sites, there has been a lot of misconceptions about how the option works, and difference of opinions about how they should work in the future.
I started: https://www.mediawiki.org/wiki/Requests_for_comment/Login_security
It would be great to get feedback on the "Longer Term Questions" section. Also, if anyone isn't entirely clear about how the preferences work, hopefully this will provide some clarification.