Is storing data in PHP $_SESSION insecure?
问题 As per my understanding, PHP processes doesn't behave as application server process. So, after the execution of a script the PHP process retains no user specific data. It instead stores them in the user's cookie. So whatever we store in $_SESSSION goes into cookies. Is this true? If yes then are they stored in clear text or some encoding or encryption is done? 回答1: No, the only thing that goes into the session cookie is the ID of the session - a random alphanumeric string. All the session