3. In practice, a lot of cookie-based auth systems are badly done, whereas the digest authentication in popular browsers and popular web servers follows a sensible design (the two RFCs mentioned) and is well implemented. However, it doesn't have a shiny user interface that site designers want.