> You're missing one method - using the user's IP address
 > It's not a guaranteed fool-proof method, but if you don't 
 > want to use cookies or the URL, then this sorta works.

Unless there's a firewall using NAT or a proxy cache involved.  I know
for a fact that our internal network only ever reports the address of
our firewall.  We run an Internet kiosk of sorts so if two or three
people hit your site from inside our firewall they will all look like
the same person.

We're not alone in doing this sort of thing.

CYA, Dave

