Mountain ViewA stolen session cookie now unlocks nothing.
Two-factor login just pushed theft one step later, onto the cookie left behind.
Chrome signs sessions with a key locked inside a device’s secure chip, so copying the cookie file alone no longer works.
The protection needs modern hardware many users worldwide don’t have.
Sources: Ars Technica