Nice article! There' s also another case in which unencrypted network are used to steal credentials: when somebody leaves the connection open and set up a proxy in order to pretend to be the server of interest, in which case even ssl wouldn' t save you because being the proxy the one that does the ssl handshake(instead of the original server), you get your credential stolen again. So it' s always better not to rely on free wifi networks, even when using ssl. And btw, do you mind offering https browsing? :D cheers!
Toggle Commented Nov 14, 2010 on Breaking the Web's Cookie Jar at Coding Horror
Nov 13, 2010