Sessions usually leave a cookie on the users machine with the PHPSESSID so that it can determine the session ID on every page. If cookies are turned off, then this cannot happen, so the ssid is appended to the URL. Some people just leave it in the URL as a default anyway, because they can 😛