EDIT: Session cookie needs to be set as "secure" and Strict-Transport-Security should be implemented in order to protect against certain attacks. End users can just add this HTTPS-Everywhere ruleset:
https://raw.github.com/mikecardwell/https-everywhere/73241d1...