I find it strange that the work to modify frameworks is being used as a counter argument. Isn't that the whole point of using frameworks, so that a change of this type would be "free" to the users of the framework? How valuable is the framework you are using if it can't make such a transition? Surely, it is harder to change all the custom cookie implementations out there than to change the frameworks which use cookie authentication? I would think that the ability to hide this change in a few common frameworks would be a strong argument FOR this change!
Posted Mar 28, 2010 10:15 UTC (Sun) by erwbgy (subscriber, #4104)
[Link]
Thanks for the link. This is an excellent paper about the Internet, the stack of protocols proposed and active and potential future problems. I would recommend others read it.