3 ms·
The cookie is not something that is "possessed". This is a case of two separate things you "know", such as a username and a password. If they added a second pas
by AgentK20 6y ago
The cookie is not something that is "possessed". This is a case of two separate things you "know", such as a username and a password. If they added a second password, it would still only be 1FA. For it to be considered a "second factor" it should either be "something you have" e.g. a physical hardware token (or to a lesser extent a phone who has a saved shared secret, although it's arguable whether that counts), or "something you are" like a biometric verification (fingerprint, retina scan, etc)