Originally Posted by
Invent
Cookies are perfectly secure if you use them properly.
Some people set a cookie with someone's username/password/etc but when they check if the user is logged in or for SQL Queries (which contain the user's account name) in the script they only use the username in the cookie. So if you modified your username cookie you could get other peoples information or go in their account.
Obviously you can stop people from doing the above by making your script secure. But some people dont (E.G Naresh & his user system).