Re: Linking a cookie to an IP address is a very bad in 2015...

> The server can bind state to the TLS
> session; there's no need for an HTTP cookie, if the site is HTTPS
> only.

I always recommend against that.  Connections break.

