What do you mean? Rails support running over HTTPS. Or are you suggesting that Rails never run over HTTP only?
It's as simple as that. Never assume that anything transmitted over HTTP is safe, because that assumption will come back to bite you.
Are you suggesting not using SSL?
If not, can you clarify your point?
Thanks.