Thought this would be interesting for others too. Not being a network guru (though I've already read the IP protocol rfc;)) I was wondering what protocol do browsers/webservers use when a requester pops up saying we are using a secure connection. Like when using Paypal. And how secure is it really ? What about if you're connecting through one of those wifi AP's someone set up (talking about intentional internet sharing here, not stealing;)) won't he be able to spy on all the data that goes through the server (same applies to ISPs ?) I mean, even if the thing is encrypted he'll be able to view the initialization process so I don't get it how a connection can really be secure for the user, at least on the provider side.