^ had a discussion about session variables the other day:
A teacher at my computer sciences - internet programming - class said session variables are safe and needn't to be checked like posts, gets, cookies, and such. His idea was that they're stored and managed server-side so are unfuckwithable.
I had my doubts but no strong points to convince him otherwise. Are there?
__________________