In my experience, many corporate developers have HTTP access to HTTPS services (either permanently or only while a test is being written.) They can record a script, change the HTTP URLs to HTTPS and then run the script.HTTPS is a problem for many of the testing tools (JMeter, The Grinder, MaxQ, etc.) There is been a lot of discussion about how to overcome this.