I got a warning in Chrome that a Javascript was bypassing https and therefore leaking its cookie etc. In the Dev tools sociable-admin.js & addtofavorites.js werethe only ones that didn't laod via https, loading via http only.
This is a security risk.
[edit - more than 1 JS file]