> You're effectively talking about an attacker breaking https aren't you?
No. There are many ways to fish bearer tokens. Encryption in transit only addresses some of them.
No. There are many ways to fish bearer tokens. Encryption in transit only addresses some of them.
Just Google for session hijacking attacks. There's a wealth of information on the topic. It's a regular entry in OWASP top 10.
OWASP's page lists 3 more examples which it seems you omitted for some reason.