Faking a cookie is quite easy actually the majority of sites ive seen have set up there cookies really easy you could probably fake them extremely easily.
Yes they are easy to fake, its extremely hard to prevent however I also havent seen something that is 100% that will work.
To be honest anything that the client can see is not safe, Cookies arent safe they are saved in a file or files depending on the browser (firefox if i remember correctly saves all cookies to one file).
Id make sure that I could prevent it as much as possible. Things like storing the last visited time, storing this within the database, first active, userid. Also make sure you encrypt this, and do not store things like credit card numbers or passwords one site i attend i found out they stored the password i havent been to the site since.