Hacker News new | ask | show | jobs
by shadowflit 5025 days ago
If you have two factor authentication but leave yourself signed in, a password alone will not get an intruder into your account, but a cookie will.
1 comments

Some web sites will require you to login again if your IP address changes, no matter what cookies you have. Additionally, the cookie expires. For these websites, the password is much better.