> A random cookie or authentication record containing your logon details for an online site, with which someone could pretend to be you? Don't you realize what it means when the browser asks you whether it should "remember" your logon name and password?
It implies saving that password on the hard drive, yes. However, any interested attacker, once gaining access to my account, can just as easily install a keylogger and simply wait for me to log in to this site the next time. Or for me to enter the passphrase for my SSH keys or GPG keys, which is likely more interesting than my HN account.
He could also access my email account and send spam via my server (because, yes, I do let Claws save my password…), or could use all the other data on this hard drive (pictures, CV, instant messaging logs, emails, etc.) to impersonate me.
Really, what’s so special about authentication cookies that they absolutely must be secured?
Okay, here’s one difference: Assuming an exploit in Opera allowing for arbitrary code execution, the OS won’t block access to wand.dat, but it will, thanks to AppArmor, block access to ~/.ssh (in fact, everything but ~/.opera and a few other select directories). Circumventing AppArmor either requires root access (theoretically possible assuming a fault in the kernel) or tricking me into running code I don't want to run outside of the AppArmor profile, e.g. by adding an exploit to a downloaded PDF file I then open in Evince.
But, uh, yes, this requires arbitrary code execution in at least one of the internet-facing applications, most of which are enclosed in their respective AppArmor profile, and then some sort of escape from said profile if one wanted to read anything not naturally relevant to the programme exploited (~/.opera/wand.dat from Pidgin, e.g.).
However, if someone is actually able to run arbitrary code in Opera, they can at least access all cookies of the current session, even if I didn't let the browser remember the password, as well as install backdoors in the browser[0] to record future logins and send them somewhere. So by not letting Opera remember passwords, I secured those passwords which I didn't use in the current session. Considering that usual sessions in Opera last about four to eight weeks for me, that gain is rather minuscule compared to the hassle of entering/remembering or copy-pasting passwords from somewhere else.
[0] Opera evaluates user-provided Javascript files in ~/.opera pretty much all the time, so it is not necessary to write to /usr/bin/opera for that.