Correct me if I'm wrong - looking at the source code, Facebook submits the form over https, though the page is http.
By itself, a leak of information may appear trivial, but piece together a few bits of info and mix in some social engineering, and you could have enough to do naughty things! Yes, users should use different passwords, but you should be the one who does the right thing and takes the responsibility for them, to prevent that exponential spread of consequences. It's more than just "This cert cost me x", it's "If I spend x, I save y people from losing z of time and money." where x<y<z.
StartSSL offer well priced certificates - from free, up to ~USD150, and they are well reviewed here: http://www.sslshopper.com/startcom-certificate-authority-rev...