Convenient, yes. Also a trade-off. Widely adopted digital identity guidance, most prominently the NIST Digital Identity Guidelines, SP 800-63B series, treated across the industry as the reference standard for authenticator and session management, holds that session secrets should not persist across browser restarts, because long-lived tokens on unmanaged or public devices sharply raise the risk of unauthorised access. Related federal guidance (NIST SP 800-209) goes further, advising that locally remembered usernames and passwords for automatic login should not be used unless handled by an authorised central authentication service.
Think about what that means in practice. Anyone with physical access to a logged-in device can open the cashier or change personal settings. So keep "Remember Me" for your own phone or private computer, and only where a device lock screen is active.
Two-factor authentication (2FA). Enable 2FA in your security settings wherever the operator offers it. With 2FA active, the platform asks for a one-time six-digit code from an authenticator application such as Google Authenticator or Authy after your email and password are accepted. The code rotates every 30 seconds, so a stolen password on its own no longer reaches your balance. Basic hygiene alongside it: use a unique password you do not reuse anywhere else, rotate it now and then, and never approve a login prompt you did not personally trigger.