GLBSE resets the session ID after login which prevents session fixation. We only whitelist certain html elements for PM's and contracts so no XSS, and we use SSL so no man in the middle session sniffing attacks. Session ID's are not predictable or unencrypted.
I don't know exactly what you mean by this, but I have Google 2FA installed.
When I log in on GLBSE en close the tab without logging out, I can re-open GLBSE after a few hours and it will come back up with me logged in, so I don't have to re-login
I do leave other tabs in my google chrome open, so I never close chrome completely
FYI
Even if you,after you totaly CLOSE Internet Explorer or Firefox, (I don't use Chrome, so can't test it) go to GLBSE your session is still active/logged in.
Actually, after you restart your computer, it is still logged in..
I have 2FA activated, but only have to fill in the auth-key when I use a 'new' computer..
As long as a 'hacker' can't use my SessionID on his own computer, I see no problem, but according to the above this ID won't change since I'm always logged in..