> you don't care if anyone can?
that's a very bald assumption, my dear friend.
But in practice, yes, it is safe do not care of the possibility that someone is going to inject a script in your blog header, because I am no police officer, I do not work overtime, fighting crime. [1]
Same way I'm not worried that someone is going to steal my car and use it to rob a bank or worse.
> Do you use online banking?
Banks also have guards at the doors.
They handle other people's money, of course they care about it and about the safety of their employees.
Are you a bank?
> Do you care if you transmit your password to your bank account in plaintext?
Not really.
99% of my passwords are passw0rd on websites I really don't care about.
It is much harder, if not impossible, to guess my username.
I bet I am not the only one.
Besides, my bank ask me to confirm any operation in a MFA way.
If they notice something strange, they call me, on my phone, a human calls me.
It's their job.
> Would you really trust a phone number delivered over HTTP?
I've trusted for the majority of my life phone numbers sent unencrypted through wires that everybody could wiretap to and then by email...
Nothing bad ever happened.
Besides, what can happen if you call the wrong number?
I do not believe that the Grudge is a real story.
The point is: no, I am not paranoid.
Common sense is enough 99% of the times.
[1] https://www.youtube.com/watch?v=o2Z1yLO9C-Q