Giving your cookies short timeouts, say 5 minutes, and including the client's ip address in the cookie are both mitigating techniques.
Plus, even with the most strict filtering client IP addresses can always be spoofed.
Maybe there is a middle ground?
This wont work, though, as nobody wants to sign in once per day. That's too inconvenient.