Compromising the client Pc, for instance by installing a destructive root certification into the method or browser believe in shop. SSL/TLS is particularly suited to HTTP, because it can offer some security whether or not just one side in the communication is authenticated. Here is the situation with HTTP transactions http://XXX