said by Mele20
:While Chase now uses a secure login on their main webpage Chase still presents security and contact information on INSECURE pages which can lead to phishing attacks. Plus, Chase still has work to do on login as it is still possible to login on an insecure Chase page but not easy like it was for several years.
The amount of "http" pages where a login is possible are considerable. One area where they may have missed the boat is on their security pages. It would make sense to encrypt those pages if for the only reason to illustrate what an "https" page looks like.