3 ms·Or mandate 2FA and password managers.by bakatubas 5y agoOr mandate 2FA and password managers.goodpoint 5y agoEven that is often not enough: sessions are long lived and very often stealing a cookie is all the attacker needs.