Re: [xml-dev] RE: Encoding charset of HTTP Basic Authentication

From
John Cowan <>
To
Richard Salz <>
Date
2012-01-30T15:51:13Z
ID
<>
Thread
Re: [xml-dev] RE: Encoding charset of HTTP Basic Authentication
Richard Salz scripsit:

> The problem with basic-auth is that it requires the name/password to be 
> sent on every single request. The more a password is used, the more it as 
> at-risk. Even over SSL/TLS.  Digest is better because it never sends the 
> password over the wire. It's worse because 

Arrgh!

> Hope this helps.

Let's try that again, eh?

-- 
Knowledge studies others / Wisdom is self-known;      John Cowan
Muscle masters brothers / Self-mastery is bone;       
Content need never borrow / Ambition wanders blind;   http://ccil.org/~cowan
Vitality cleaves to the marrow / Leaving death behind.    --Tao 33 (Bynner)