I'm my example it was the other way around. You load an insecure page over HTTP without triggering any visible warning. And then you load a secure iframe over HTTPS with a login form and this triggers the "Not secure" warning.
The only reason to do this that I can think of is because of MiM attacks like detaro wrote about.