Yep so it means my ISP can know my password on this site? (Including HF?)
If you are so worried about security on a message forum you have several options.
1) For Firefox users, check out the HTTPSEverywhere addon, can be found at the Electronic Freedom Foundation (eff.org)
2) HTTPS only encrypts traffic so far, SSL is pretty easy to man in the middle at the ISP level as they can Deep Packet Inspect all your traffic if you are doing things online to arise them being suspcious of you to require all your account traffic be inspected or have been instructed by Law Enforcement/Court Order
3) Really worried about your privacy on a forum site, check out Tor Browser, though a lot of suspicion and misinformation surrounds Tor and the Tor Browser, there is not much to worry about using Tor and its browser at default settings, leaving the browser run at its default resolution/screen size. Minimum your traffic routed and relayed with 3 nodes between you and your site you are visiting and at each junction the traffic its encrypted and encapsulated at least three time so no Tor Nodes/Relays know what data is being piped along its network, you to Tor Node 1 (3x encryption encapsulation), Node 1 to Node 2 loose one layer, Node 2 to Node 3 lose one layer, Node 3 to Website last layer is shed, Website to Node 3 (3x encapsulation again), Node 3 to Node 2 lose one layer, Node 2 to Node 1 lose one layer, Node 1 to You lose last layer. About every 10 minutes your Node Circuit path will change to a new entry, relay, and exit node on the Tor Network, this makes sure pretty much you are encrypted end to end, and your traffic is masked over by ambiguity with other users. Only downside I see using Tor Browser is the browser is a couple versions of Firefox browser mainstream, but comes with HTTSEverywhere installed and disables javascript, flash, and other entry for hacking by default.
4) Mentioned above earlier was using a VPN provider, you'll have to shop around for a good VPN provider, look for one that does not log traffic or retain traffic logs longer than 30days, and read their privacy and usage policies thoroughly. A good VPN Provider, for about 30 to 50 USD annually, you get a far more highly encrypted traffic stream your ISP or any other man in the middle must take a lot of work to deep packet scan your traffic, the traffic is encrypted end to end, and the VPN Provider node you connect to becomes technically a proxy node, the websites you visit see the VPN node ip address, not yours, also, you can further anonymize yourself tunneling Tor through a VPN Provider. How paranoid you are, choose your privacy practices to suit them.