OWASP's Secure Coding Practices Checklist mentions
Only send non-temporary passwords over an encrypted connection or as encrypted data
I can understand why permanent passwords are sent encrypted, but I cannot grasp my mind around why temporary passwords shouldn't be encrypted.