Web applications are stateless - if you want to check uniqueness of visitors, you *must* implement something, whether it's cookies or email address, or something else. Even these aren't enforceable enough for stricter applications. The IP isn't enough - AOL's proxies use several per individual, and people on shared internal NAT's all appear as one. You could try IP + user agent, but it's still pretty weak.
-----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Sent: Wednesday, May 23, 2007 9:18 AM To: CF-Talk Subject: Voting only once - how to enforce ??? I'm creating a voting application for a photo contest and the non-technical person running the show doesn't want voters to have to verify their email address before their vote is counted. Although this method isn't fool proof, it does create a level of effort to break the one vote rule. Does anyone have any ideas on how to ensure that voters can only vote once and not rely on cookies being enabled, deleted etc. Thanks. D ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~| Create Web Applications With ColdFusion MX7 & Flex 2. Build powerful, scalable RIAs. Free Trial http://www.adobe.com/products/coldfusion/flex2/?sdid=RVJS Archive: http://www.houseoffusion.com/groups/CF-Talk/message.cfm/messageid:278977 Subscription: http://www.houseoffusion.com/groups/CF-Talk/subscribe.cfm Unsubscribe: http://www.houseoffusion.com/cf_lists/unsubscribe.cfm?user=11502.10531.4

