What are the attack vectors for passwords sent over http?
- by KevinM
I am trying to convince a customer to pay for SSL for a web site that requires login. I want to make sure I correctly understand the major scenarios in which someone can see the passwords that are being sent.
My understanding is that at any of the hops along the way can use a packet analyzer to view what is being sent. This seems to require that…