I will also point out that this system will work alongside openid and our servers will not be storing details such as credit cards just emails, usernames and bio information, not that that makes a difference in data protection. php security session authentication share|improve this question edited Jan 17 '12 at 21:28