Storing session information in permanent cookie

(06-23-2017, 05:08 AM)CINewb Wrote: I did, but I wanted to point out to the OP the scenario of shared computers, since people often only think about a single user sitting at a single computer. Someone using a shared computer for 5 minutes is likely to be better protected with a session cookie, compared to a persistent cookie (albeit with an expiry time of 20 minutes).

I realise it's not black and white, I am just pointing out a scenario that the OP might not have thought about.

So, whats your point? What if someone is using a public computer but does not close the browser? You have the same result as using a persistent cookie. Atleast with the persistent cookie of 20 minutes it is invalid after that time. The session cookie remains valid as long as the browser remains open. So how is that better?

