4 ms·
Not if you need to support HTTP Digest authentication.
by drrotmos 6y ago
Not if you need to support HTTP Digest authentication.
- merb 6y agowell http digest auth is stupid. it looks more secure because the password is not sent unencrypted over the wire. however it still is bad. kerberos or even basic auth (because the password can be checked on the server against a real algorithm) would've made this impossible.