HTTP cookies, or how not to design protocols - http://lcamtuf.blogspot.com/2010...