I have been using Tor as my HTTP proxy for searching and it works great, but nothing prevents the Alt.Binz authentication from being sniffed at the exit node.
I am able to sniff out the x-www-form-urlencoded request used for authentication. The username is sent in plain text, and the password, while hashed, stays the same every time. I am concerned that this could lead to a compromise.
I'd like to suggest a secure authentication system. Thank you for Alt.Binz!