Re: [moore@cs.utk.edu: http digest auth + http 1.1?]

I agree with Dave Krystol's position: if a client supports
authentication at all, it MUST support Digest.  This means that only
those supporting authentication must do work, keeping the simplest
web clients simple.

We have to get passwords in the clear out of use in the Web; naive people
tend to put their regular passwords into password fields, not understanding
the lack of security.
				- Jim

Received on Monday, 26 August 1996 14:43:42 UTC