None
NL
Account hijacked despite 2FA: a stolen cookie is enough
['Steffen Zahn']
Notebookcheck.net: Article RSS Feed
That file is the session cookie.
An SMS code, an app prompt and a security key all check who is signing in.
Anyone who stays signed in may not be asked for the security key again, according to Google.
Total Cookie Protection does not change this, that is tracking protection.
A new password does not necessarily throw out an attacker who holds a valid cookie.