I get that this in normal scenarios this cookie wouldn't leave the machine, I get that it's very convenient to not have to log in all the time, I get that Slack people know this stuff a lot better than me... but it sure seems like a weakness to have single point of failure to leak your slack channel by losing a cookie. Isn't it?
Maybe there is a middle ground?
This wont work, though, as nobody wants to sign in once per day. That's too inconvenient.
Plus, even with the most strict filtering client IP addresses can always be spoofed.
I don't know about a giant company like EA, but you could really screw with my company's plans if you spent any time on our Slack.
So now I need to consider that any malware could (and probably is) looking for slack cookies to exfil. So, no, I don't really believe there is always going to just be a single point of failure and it's an insurmountable problem.