Gmail credentials are supposed to be delivered over an encrypted connection. Controlling the network should be insufficient to see passwords in transit. That said, passwords are a poor form of authentication that is prone to interception by poorly configured clients, HTTP downgrade attacks, and typosquatting login forms. I wouldn't jump straight to "0day".