It's bad because when someone suspects unauthorized access to their account, the first thing anyone recommends is to change your password. If the old cookies keep working, changing your password doesn't help.
I always wondered how they addressed the state problem of cookie bearer tokens.