>My only real constraint is that it has to use the storage API to be considered for inclusion. But the storage method would have to be server side and not associated with a session for this to be meaningful, right? Otherwise as an attacker, can't I zero out any client side storage/cookies and bypass the entire protection mechanism? --- Eric