ben_thatmustbemeif you are logging in to a system without https.... all you post is your URL, that redirects you to https on indieauth, where you have actually auth, but the redirect links back to your site are able to be sniffed and thus gain access