If you're not using SSL, you should just assume that an attacker can break your page in every conceivable way.
If you're not using SSL, you should just assume that an attacker can break your page in every conceivable way.