after there is such a nice tool for dummies to hijacking sessions: http://codebutler.github.com/firesheep/
I thought this needs to be addressed with a simple rails3 plugin to enforce the use of ssl
http://rubygems.org/gems/enforce-ssl
maybe someone finds this also useful - enjoy and.or give feedback Kristian