While a login to a site may be conducted via a secure session, many sites then drop you back into an unprotected connection in which a token stored as a browser cookie ensures the continuity of your actions from page to page. That token is vulnerable.
Firesheep turns sidejacking into a click-and-install demonstration with 26 built-in site profiles to snarf. I explain Firesheep, sidejacking, and how to defend against it—using notions of security I've written about on this site for years—in an article at BoingBoing.
Decaf on the Starbucks Digital Network