LWN.net Logo

Should web developers say no to cookie-based authentication?

Should web developers say no to cookie-based authentication?

Posted Mar 25, 2010 16:58 UTC (Thu) by epa (subscriber, #39769)
In reply to: Should web developers say no to cookie-based authentication? by ras
Parent article: Should web developers say no to cookie-based authentication?

I understood

3. In practice, a lot of cookie-based auth systems are badly done, whereas the digest authentication in popular browsers and popular web servers follows a sensible design (the two RFCs mentioned) and is well implemented. However, it doesn't have a shiny user interface that site designers want.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds