Comment Hmm.. (Score 1) 576
So, if they're using this hash as a type of public key then the private key would be transmitted after connecting with the server. Thus you just have to catch the public key whizzing by and handle the initial server interaction then you could monitor it on your own. But thats assuming it is a key type setup like https is. Man in the middle ftw?