We use one inoffensive session cookie.
Logon