The point is to prevent your actual password from being sent in the clear. Yes your session could still be hijacked, but most websites will at least require you to re-enter your password (over SSL) to change your key profile attributes or password, meaning the most someone can do with a hijacked session is vandalize the site from your account. If they have your password via sniffing, they can instantly do a whole lot more, especially if you use the same password everywhere, regardless of the merits of doing that.