Store passwords as the MD5 hash of the password, not the value.
Be sure that all connections are secure; ignore any that aren't, and redirect the user to a secure URL.
If your server connection is SSL-encrypted (and you check!), then you can be reasonably assured of privacy across the net, at least for data of the level of security any of
us are likely to have to deal with... (
i.e. If you've got a TS-Crypto clearance then presumably you've also already been trained already on the correct procedures for
that sort of thing...

)
{Hi there, Tom Ridge! How's the kids? No, sorry, this is
not a terrorist post. Better luck next time...}

...

...

... (Ooh, I hope those boys have a sense of humor.)
