Take your pick. POST, SESSION, whatever. Depends on the nature of your data and desired security, and, really, true security with any of these is near nil unless you're encrypting the traffic. But if you're not dealing with credit cards or bank accounts, perhaps it's no big deal?
I suppose that SESSION might keep them from playing around with some values, if they were inclined to do so. Mostly, I use the POST array.