You are also clearly neglecting the fact that proper session cookies are _always_ cryptographically signed and cannot be tampered with, if properly implemented.
But still, if your frontend hosts can't reach your database, you have far bigger problems than your sessions not working.
I agree that simply storing everything in the cookie is wrong, and Rails should never have been doing this - hell, even CodeIgniter (PHP) has DB based sessions.
But most Rails devs (myself included) are just about getting shit done, we don't know everything that's going on under the bonnet, and we don't want to.
I love getting shit done.
It's my job as a professional to know everything that's going on "under the bonnet."
I'm still learning.
But it's my job to try.
And FYI CookieStore is just the default, because it's convenient and require no dependency. But you're juste a line of configuration away to switch the sessions inside your DB or Memcache or whatever.
It's not that hard to just set up a Redis or whatever store to handle stuff like this, I never understood why people whouldn't bother.
All session stores use a cookie to store a unique ID for each session...For most stores, this ID is used to look up the session data on the server, e.g. in a database table.
(obviously you'd substitute Redis for the database table mentioned above)