The security implications are limited, as discussed in the other thread. Although it's unlikely to happen, some protection from anyone trying to foobar a user's authentication by the server would be welcome (beyond the obvious evidence of the logs). But this is a problem no matter if sent over SSL or not, as long as real user names and uids are used ...