Re: HTTP/1.1 + Digest

Larry>

>Writing MUST instead of SHOULD in the specification is not any way to
>force some vendor to either implement or not implement something. The
>spec should say what makes sense, not what is politically
>expedient. We should write "MUST" if non-compliance causes systems to
>break.

This is the case here. Sending passwords in the clear causes systems
to be susceptible to security problems that they would not otherwise
be vulnerable to.

Having one's system hacked is a pretty extreeme form of having it break.

	Phill

Received on Tuesday, 27 August 1996 17:35:18 UTC