Reputation: 2577
I'm storing a lot of sensitive information in it. Is it something that can be seen by end-user?
Upvotes: 1
Views: 844
Reputation: 3689
No it cannot. It's fine to store sensitive information there. In fact - it's where .net membership creates the User object for authentication.
http://msdn.microsoft.com/en-us/library/ff650037.aspx
Upvotes: 2
Reputation: 416
Actually no. The session informations are in your server. Hidden html objects (including view state), cookies or your querystring can be seen by end - user
Upvotes: 1