How you can get hacked if you are using iPad/Safari/gmail
blog.secpanel.com
blog.secpanel.com
The ones that grant access to your account are named "S" and "GX". You can prove this by a process of elimination. Delete a cookie and see if you get logged out.
They're set on "mail.google.com", not "google.com", so they don't get sent when you search. Furthermore, they're marked "secure" so they only get sent over HTTPS.
Or should I always avoid http://google.com while logged into a google property on untrusted networks?
1. session cookie hijacking not possible
2. the iOS mail app supports encrypted email
Another temporary workaround is to set the default search to Yahoo or Bing, to help train you to use an SSL-enabled bookmark. That is, unless you happen to be logged into either of those services.
The authentication cookies for GMail are named "S" and "GX". They're both set only on "mail.google.com", and they both have the secure flag so they're only transmitted over SSL.
There are certainly other Google cookies that let them track your identity that will get sent when you search. But those cookies are not sufficient to get access to GMail.