When logging in to Gmail, if you request the login page by specifying https explicitly in the address bar, as:
https://gmail.google.com/gmail
then your entire Gmail session will be encrypted, not just the password authentication handshake. Cool, eh?
Update: This tip will also help solve any problems with connecting to Gmail from China.