This one has been resolved but not solved. Set var $live_site to https and the security warning is no longer displaying. However, now my entire site is https instead of just the login and registration. I really don't want the entire site https but would rather have that than getting warnings and errors and potential for unsecure password posting and registration.
It appears that whatever is calling
www.mysite.com/components/com_comprofiler/js/cb12.min.js
?... is not recogizing the settings in the cb_login module.
changing the live_site setting in joomla's configuration.php file is not recommended.
We have the same setting on this site (registration page goes to https and stays so) so that we are PCI-DSS compliant, but we don't have the issue you mention, and we are running CB 1.4.