I've been looking at the issue from a customers perspective.
With PayPal Standard, they leave your site after giving all needed details and go to PayPal with the **exact **cost of everything, including shipping etc.
With PayPal Express, they log into PayPal to obtain a 'token' without knowing at that stage, what they will be charged. Incidentally although Firefox is ok, having checked further, IE6 still throws up a warning flag if returning from PayPal Express to a non SSL site?
Although I put my hands up and state that I don't have SSL on my sites, I limit the data I capture to just name and address. I know some people will look down on that, but seeing as much of that data is also transmitted by email, in the order confirmation from the site, as well as in the payment confirmations from many payment processors, it does somewhat negate some of the security issues?
Looking at the two methods of PayPal side by side, there are plus and minus points to both. For repeat orders, customers just need to enter their site user name and password to log in. At the moment I am tempted to go with PayPal Standard, for no other reason than I like the idea of customers knowing what they are paying when they go to PayPal.