Just noticed as well that it doesn't force you to use HTTPS for the login, so if just go to mtgox.com without explicitly using
https://mtgox.com you may be submitting your username/password oven an unencrypted channel.
I use the httpseverywhere plugin from the EFF - it forces https if it's available, so I never noticed that. Good spot!!