Piwik should work nicely when loaded in https (SSL).
It would be nice to have an option to force SSL login, so that login data is always sent encrypted.
Maybe we should, if possible, check that SSL actually works at all, to prevent non ssl compatible setups to set this to true which would then prevent logins.
Note: this is similar to wordpress wp-config hack FORCE_SSL_LOGIN
Propose also settings the Strict Transport Security header per the IETF draft.
FireSheep is making news. I think we can implement this for 1.1.
Strict Transport Security is a wontfix (out-of-scope):
(In ) fixes #1677 - added General force_ssl_login setting to global.ini.php (defaults to 0, disabled); this applies to login, lost password, and reset password forms
I opted to implement this as a config file option (instead of via General Settings), as it ensures the sysadmin has file access to change the setting, in the event the secure login doesn't work (e.g., no virtual host listening to port 443).
There are two aspects to the patch in order to handle reverse proxies:
How do I force Piwik login to use SSL (https)?. Let me know if any feedback.