Ideally I would prefer using Cookies only, but I am security conscious. If any, what are the down sides to using only Cookies or only Sessions, and does mixed really add best of both worlds or is it really just for compatibility?
Also, for users who have an IP that changes regularly (Dial-up), should I disable “Require IP Address and User Agent for Login?” to prevent these users from being kicked when their IP changes?
Thanks.