The only clarification I'd make here is the distinction between "public wifi" and "unencrypted wifi". Some cafes I frequent have WPA2 secured networks with the SSID and password made freely available. I'm pretty sure that solves the Firesheep problem (I don't know for sure, but I'm reasonably confident that other people on the WPA2 network still can read my connection).