Also, grandparent assumes the choices are JS crypto and sending passwords in the clear, ignoring the SSL/TLS option.
What am I missing here? Are people to cheap to purchase an SSL cert? Theoretically the PKI is only as trustworthy as the CAs but that can't be why people are acting like SSL/TLS isn't even an option.