If my understanding of Pyramid is correct the function of remember is entirely dependent on the authentication policy your project is using, so the security depends on which authentication policy...