Business lending website LendVantage (endorsed by Larry King!) collects business and personal information as part of its pre-approval forms. Along with business details, income, names, and addresses, the site asks for your date of birth and Social Security Number. The site loads over insecure HTTP, and POSTs over insecure HTTP.
On an open or masquerading wi-fi network, all of this unencrypted and unprotected personal data would be exposed to an attacker using network sniffing tools. LendVantage should use SSL (HTTPS) for both page loads and form submissions.
(Submitted by Steve)















