I'm implementing my first user login and I've read some posts here on Stack about the convenience of store login infos in sessions or cookies, but my main question is still there: is it so unsafe storing the userID/userCode in a cookie to let the user stay logged in?
In other words, is it possible to download the cookie on a pen drive, downloading it into another PC, connect to the website and be recognized as logged in? If so, how giants like Facebook and Amazon had implemented this system avoiding security issues?
Should completely avoid, then, the use of cookies for this purpose in favor of sessions (although the user has to log in every time)?
Since I have to collect sensitive informations I would like to build the safest system I can.