0

Can Traffic spy see the username and password of client send to broker when broker don't use TLS ?

hardillb
  • 12,813
  • 1
  • 21
  • 34
behroozbc
  • 153
  • 9

1 Answers1

3

Yes, without TLS the CONNECT packet is sent in the clear so all of it's content can be seen.

A full breakdown of how to decode the CONNECT packet can be found here

hardillb
  • 12,813
  • 1
  • 21
  • 34