I've heard somewhere that if someone gets a cookie off your computer for a particular website, they can bruteforce the md5 hash with something called a rainbow table and that will reveal your password, or garble that will function as a password for your user_id, is this true?