Ohh yeah on page http://www.cryptohaze.com/passwordsecurity.php "Password Storage: You're doing it wrong if: .... You let users log in with plaintext passwords over unencrypted HTTP." Don't you do that?

POST /forum/ucp.php?mode=login HTTP/1.1
....
Content-Length: 86
username=sc00bz&password=password removed&login=Login&redirect=.%2Findex.php%3F
Users browsing this forum: No registered users and 0 guests