Quote Originally Posted by DragonFlyy View Post
Packet snooping. Your username and password are transmitted as plain text. It's not the easiest way to get the information, but it is one way and you wouldn't even have a recourse against it. Hence the use of a security token that changes every use/thirty seconds.

However, the most common way of getting passwords is through social engineering. Look it up, it's rather interesting.
Nope.
/10char