The Problem (TLDR Version)
Unless you type in "https://" every time you visit FAF, or have HTTPS everywhere installed, everything you do on FAF, every bit of text you send, including your password, is plainly visible to anyone on the internet, possibly reading it over wifi, or through...