> If someone is logged in and then back to normal http, someone can just grab the cookie and pretend to be that person already-logged-in.
If the cookie is set through HTTPS, the browser won't send it when loading HTTP resources. So the cookie won't be exposed that way.
We should still be using HTTPS for all traffic in 2016.