What would the alternative be? Not warn users when they're about to login to a website that's pretending to be their bank?

Clearly the alternative is to return to HTTP, as these users are suggesting.

Surprised they're still posting, with their employers being shut down at the moment and all.