OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

 


 

   RE: [xml-dev] Re: Cookies at XML Europe 2004 -- Call for Participation

[ Lists Home | Date Index | Thread Index ]

On Tuesday, January 06, 2004 10:47 AM EDT, Elliotte Rusty Harold
wrote:

> Why not? Also a good question. I think it's mostly a matter of 
> history and unfamiliarity with the design and technology of the Web, 
> as well as inertia.

Hello Harold:

In addition to HTTP authentication not being deployed due to lack of
popularity or experience with it, there are the recent "phishing"
exploits publicized, with warnings published by E-Week:
 http://www.eweek.com/article2/0,4149,1409700,00.asp
 http://www.eweek.com/article2/0,4149,1399670,00.asp

and Microsoft:
 http://support.microsoft.com/?id=833786

This will not promote usage of a technology when you are warned about 
its use (quoted from the above Microsoft Knowledge Base Article):
"The following list shows some of the characters that may appear in a 
URL that could lead to a spoofed Web site: 
%00
%01
@"

Made me have second thoughts about deploying HTTP authentication.  Shame 
we have to deal with this.

Regards,
Ralph




 

News | XML in Industry | Calendar | XML Registry
Marketplace | Resources | MyXML.org | Sponsors | Privacy Statement

Copyright 2001 XML.org. This site is hosted by OASIS