Am I right, the cookie corresponds to the user's password? Someone who gets the cookie, can login as long as the user does not change the password?
I am wondering, if this is less or even more secure than the random value.
For mobil applications it may be more secure, because I can change my password at home, where nobody can see this. Outside I stay logged in. If my phone is stolen, I have to change my password as soon as possible. Correct?