Session Hijacking

It looks like it may be possible to hijack a crowfall.com session by stealing the session cookie using a man in the middle attack.


It just doesn't make any sense to not use full end-to-end SSL for a forum like this; latency is irrelevant and there aren't ads to run afoul of.


This game is very likely to be a target of hackers (i know Anonymous like this sort of game), and every precaution seems justified.

