For those of you stealing your neighbour's unsecured connections, you know that normal http (not https) URLs have no encryption, and send passwords and cookies in clear text? Even loading a single GFY thread should be enough to capture the relevant authentication cookies and allow someone to impersonate you.
Then there's more important things like sponsor logins......
