You can also validate the IP of the user for the session. Since many people are still on dialup, they do not have a static IP and therefore its of little value to store...but it should remain the same for the session.

IP addresses are pretty much worthless unless you're on an intranet where you can control them.

The IP address of a user can change in the middle of a session and multiple users can have the same IP address (using proxies, for example).

I wouldn't rely on them for anything.

