Not a fan of playing the odds when this level of risk is on the line.Technically this is true, but SSL accelerators are almost ubiquitous in the enterprise. Probably not worth worrying about.
If you aren't actively logging in, you're almost certainly sending a session cookie. That cookie can be lifted and your account hijacked that way. This is why your password is often required to change your passwordin case someone lifted your session cookie through other means, they will be required to provide the password which they wouldn't know in order to take possession of your account.Just to make sure: even if I access a website where my password is cached I'm still logging in and can be vulnerable to this type of attack?