The server runs on plain HTTP and sets cookies without the Secure flag, exposing session IDs to network sniffing.