in rails the default session store uses cookies. the session is marshaled and signed with a secret key so that client can\'t temper with it. this approach is very scalable a
Connect 2x has one built-in and this is an example of how simple it would be to get something basic going with Express 3x with the new signed cookie support. You can still do the same thing without upgrading but you'll need to use utils instead of those getters