@Jeffrey Goldberg Pardon my ignorance, but wouldn’t it be at least prudent to encrypt using the…
Scott Yates
23

Liam Gladdy You assume that no system will ever be misconfigured or have issues with the loopback, there very well could be. Another issue is if I have another program that listens on the loopback interface can I exploit that program and use it to sniff the loopback interface, I may not have full escalated privileges or maybe the program can only do a small function of things but maybe I can get it sniff the loopback. What is the firewall vendor on my laptop seeing and what is it sending back. There are a hundred whats if’s.

I’m not saying this is a massive security issue, I informed people they send clear text back via a loopback interface. If that bothers you then uninstall the extensions or pick a different product. If it doesn’t then go on your merry way.