It's as simple as that. Never assume that anything transmitted over HTTP is safe, because that assumption will come back to bite you.
Are you suggesting not using SSL?
If not, can you clarify your point?
Thanks.