For the ones not implementing https at all, all they have to do is be anywhere on the network between you and the server (could be the public wifi you are on, could be a compromised node anywhere in between) and “sniff” the plaintext traffic. For the ones that aren’t validating the certificates, it would be slightly…