Another solution my guts believe is safe is (I have no formal proof) to replace http://.../signin by https://.../signin?uid=123456798123456798.... With the uid to be a huge random unique key. TLS makes sure nobody can read the url, so your uid/ukey is safe on the wire. Bookmark it. Make sure your laptop is not stolen. (anyway...) Done.
Sep 6, 2011