- Add session limit, add new status code for refused - Ramdomize session ID, prevent dups - Make session IDs immutable