Should web developers say no to cookie-based authentication?
Posted Mar 25, 2010 16:58 UTC (Thu) by epa (subscriber, #39769)
[Link]
I understood
3. In practice, a lot of cookie-based auth systems are badly done, whereas the digest authentication in popular browsers and popular web servers follows a sensible design (the two RFCs mentioned) and is well implemented. However, it doesn't have a shiny user interface that site designers want.