|
Before you get too far with your assumptions, I believe that you should validate the the transmission of data is in fact "in the clear".
If it were me, on the system that I am using to lookup data on their system I would install wireshark and perform a packet capture when retrieving some records. If you parse that capture for any of the information that appears on your screen and get results, you then know that there is a problem. If not, go get a drink and relax.
|