A stolen session cookie now unlocks nothing.

Two-factor login just pushed theft one step later, onto the cookie left behind.

Chrome signs sessions with a key locked inside a device’s secure chip, so copying the cookie file alone no longer works.

The protection needs modern hardware many users worldwide don’t have.

Sources: Ars Technica