Cedar Cox <cedarc(at)visionforisrael(dot)com> writes:
> So. If working with sensitive data, shouldn't the data be encrypted as
> well, not just the login sequence?
Yup; see SSL.
IIRC this was one of the reasons why a sniff-proof password security
protocol didn't seem like a critical issue.
regards, tom lane