once you login and the fact that you're logged in is passed around via a cookie, unless the entire interaction with the website is over HTTPS, the session can be hijacked in any wifi coffeehouse, rendering the limited usage of HTTPS mostly pointless.