I am using Sessions. The Session is placed in a cookie, but it was not working, I guess because of that dang P3P policy thing. I installed P3P, but the cookies still don't work 100% of the time, it's like they pick and choose when to work and when NOT to work.
Now I am passing the Session Id in EVERY link. That is not good, because if someone was able to get the Session Id from the packets, they could take over a session. Part of the reason of using a Session Id being so long, is to make it hard to guess. but being passed in every url, secure and not secure could be bad.
Is there a way to make it work ONLY with that browser, but where it won't work if it's on another, such as a different version, or a different "platform" or a different IP?
Or just something where it cannot be hyjacked?
Or do you think it's pretty safe to pass them in the browser? I do see a lot of sites do that, but Don't know if I like it.
What do you think about it?
Thank you.
Richard