The problems you indicated are not resolved in the absolute sense. The server is not 100% secure, and each man-in-the-middle attack can be made even further.
. , . , session_save_path() , "/tmp" .
" ", uber- , . - . , .
. , . , . , , , . , . , . , . .