Hehe, good point b10m. So is the only way to pass things like this securely by storing them in local files inaccessible to the user since you can't pass anything between instances of the script (non-persistant environment) and you shouldn't pass anything as a value (not secure)?