Thirding this some time later. :) HTTPS should be near mandatory when dealing with authentication or session identifiers to prevent needles account compromises.
Thirding this some time later. :) HTTPS should be near mandatory when dealing with authentication or session identifiers to prevent needles account compromises.