Using an HTTPS connection is all well and good, but it is not enough. HTTPS is susceptible to man in the middle attacks [1], and securing the params with a pre-shared secret key is essential.
The extra cost in 'complexity' is really far outweighed by the (warranted) extra security.