Earlier quoted context omitted.
you are screwed either way. that is what Firesheep does the solution is to use SSL and set the secure flag on the cookie
I mean what if some one steals your cookie from your machine and copies it to his machine, this way he can login as you. I feel there is a way to prevent this, but I have no idea
no way to prevent it, just the way it works. there you are relying on local machine security and the user not keeping themselves logged in, etc.
do use SSL, though