I would NEVER save a username/password in a cookie, which a user can read on their PC if they know how. I would store a GUID in a cookie and in your DB, associate that GUID with a login id. This means the client side doesn't have the username/password combo, but you can log them in.
Christian Graus Please read this if you don't understand the answer I've given you "also I don't think "TranslateOneToTwoBillion OneHundredAndFortySevenMillion FourHundredAndEightyThreeThousand SixHundredAndFortySeven()" is a very good choice for a function name" - SpacixOne ( offering help to someone who really needed it ) ( spaces added for the benefit of people running at < 1280x1024 )