A friend of mine had a job interview and was asked few multichoice questions. One of the question was
Which of those can be manipulated on client side: cookie data, session data, remote ip, user agent
I'd say that session is the only one you cannot mainpulate (I mean, you can hijack it etc but you cannot change it's data as questions suggests)
What do you think?