Hi!
Thank you for the post. You are correct that it's important to secure users cookies with a 100% https website.
As you observed older pages are not https secured. This is because as we're rolling out the new design/new sections of the site we are ensuring they are all forced to https one at a time. Unfortunately we can't just switch the site to https entirely as it would throw a lot of security warnings which is highly detrimental to visitor retention. It's going to be a gradual process and takes time.
I know this is not ideal, however we don't consider our website to be a high value target (if someone did hijack your cookie there's not much damage to be done). So for this reason we think the gradual change to https is satisfactory.
Tom