Please stick to what you know and don't talk rubbish! You are no expert in cyber security, and your research is full of crap. The sites which you said are secure, have all sorts of vulnerabilities all over them, the most simple one is, they are mostly running on http instead of https. Physical access to a machine is required to hijack a session the way you put it. If a hacker has physical access to a machine, they don't need the bloody browser to exfiltrate vital info, there's thousand other ways. You are call FOGET not FORGET! ---DECRYPTED---