How dangerous is plain HTTP?

Usually I try to tell people not to input any data on websites that are not secured with HTTPS.

That's good advice.

Given how efficient SSLSTRIP is and that most people are secured by Wifi access control. How bad is it really?

For people who follow the above advice, SSLSTRIP has no effect because they (should) notice that their browser is not using HTTPS.

How easy is it too intercept HTTP data?

With a rogue access point it is very easy. With a rogue cable modem on the same network, it is possible but difficult. DSL is harder as the lines are dedicated.

Tags:

Http