Cookies are clearly not the only solution. Cookies are stripped at some security firewalls, so you'll likely break it for a legitmate user if you do that. See my post on Encrypting or Hiding Certain Info in a URL for the full list of "can" and "don'ts".