random: I like Bugzilla’s new restricting sessions to a single IP option. You’d think this would be something that’d be built into say PHP’s default sessiong handling (and how about signed cookies or noncing? that’d be nice too) TODO: look for or write secure session handling library