Compromising the consumer computer, including by putting in a destructive root certification to the process or browser have confidence in retail store. SSL/TLS is very fitted to HTTP, as it can provide some defense regardless of whether only one aspect from the conversation is authenticated. Here is the situation with http://XXX