On 11/10/12 2:00 PM, "Jim Fox" <fox at washington.edu> wrote: >"Message Authentication Code", usually a one-way hash of the rest of the >cookie, making it an HMAC. Yes, it's a keyed hash. Forging a value requires knowing the key to the hash. -- Scott