Chase, American Express, Office 365 vulnerable to cookie replay attacks

You are Bob. I am Alice. Although we can’t see them, two others – Eve and Mallory – are reading over our shoulders. Eve is feeling evil and Mallory is full of malicious intent. Both Bob and Alice have accounts with financial services we access via the Internet.
