> Usage of unencrypted Google Analytics + Google cookies means that you don't need to eavesdrop on individual connections, just one small set: the endpoints to the Google Analytics servers.
Admittedly, it is a smaller number of endpoints than monitoring every site in the world (that much is obvious), but it's not one or two -- they're all over the place.
But even ignoring that, it really comes down to one thing: Google Analytics can't possibly make an HTTP site any less secure or less private -- you're sending a postcard with your personal details on it a million times a second! It may in some situations make it slightly (very slightly) easier for someone to snoop on a tiny bit of info about your traffic, but the fix for this isn't to make that harder, it's to make it harder to snoop on your traffic entirely. We already have a solution for this: ubiquitous TLS.
IMO, this is slapping a band-aid where your arm used to be; trying to increase the privacy of HTTP sites is a fool's errand and a complete and utter waste of time.