> Bind Sessions to IP Addresses
As they admit, "IPs... change for legitimate reasons", so it seems like most sites wouldn't want to roll out this protection, because it would randomly logout their users. I haven't tested this, but it seems like this would be pretty common on mobile networks from some googling.
> Bind Sessions to Devices
They say they will "investigate binding the session to a specific device"; is there a known good way to do this? I could imagine attempts to do this breaking legitimate use cases like Apple's Handoff between iOS and Mac, or just not adding much security.
My instinct is that the admin functionality could be put run behind a VPN, and that would be a good defense against a HackerOne employee's credentials or sessions cookie being leaked.