I am going to try to combine everything that was said in the comments into one answer. As such, please show some other users some love by enhancing their answers / comments! I will also give a brief overview of how sessions work to make the answer useful to a wider audience.
-, . PHP, , , PHP- $_SESSION superglobal. cookie .
, , . , cookie . , ! , , , PHP . , SSL , cookie SSL, HTTPS. .
, , , . , - 10 60 . reset - , , .
(.. " " ), cookie, . , , , . , , . , . , , . , !
:
- .
/dev/urandom, , mt_rand, - "", SHA1 . - (, PBKDF2 bcrypt), . SHA1 MD5 - !
- , , .
- cookie .
- , cookie- , - cookie, , 2, . , .
- ( 1).
script, (, 3 ) . , .
-, OWASP.