Is there any good solution to this? One suggestion I like is adding a secure padlock style icon for traffic over HTTPS, but that doesn't cover every case.
You have to know more than if the page is HTTPS. I could put a fake facebook page on https://evil.example.com. Normal users could go to it, see the HTTPS icon, see that it looks the same as the facebook login page, and think everything is OK.