Why would you not use HTTPS? At minimum? It doesn't take a genius to figure out how to launch a man in the middle attack and watch traffic from these devices. I'm actually surprised someone hasn't created a tool that just sniffs requests from apps, whilst stripping out important information.

