in reply to CGI Security Advice Sought
Both of these can be snooped, but at least you can detect when someone is trying to circumvent your security, by spoofing the cookie.
It might be even if you are changing the cookie hash 'often'.