Ok, so it looks like the only defence on this is to have the customer type out https? It has to be encrypted right from the get go?
It sure looks like it.