4 ms·
As others have said, things like CSRF can easily be an issue with cookies as well. The deciding issue has always been UX for me. If browsers had done a bit mo
by dasmoth 8y ago
As others have said, things like CSRF can easily be an issue with cookies as well.
The deciding issue has always been UX for me. If browsers had done a bit more on this in the early days (in particular, a logout button), HTTP Auth could have been a compelling alternative. I think that ship sailed about 20 years ago, though...