I would suggest you read merlyn's column on cookie management - it's the best advice on how to employ cookies I've yet to see. Basically, you shouldn't rely on the user agent for any of your authentication system's tasks, just use a cookie to uniquely identify a browser, then use its ID to look up the session data in whichever form of serverside storage you choose.