Subject: Re: Remembering Passwords in IE
From: Mikael Olsson (mikael.olssonENTERNET.SE)
Date: Sat Apr 01 2000 - 15:34:37 CST

Bluefish wrote:
> I think the authors of the HTTP RFC assumed stupid
> coders on the client side and intentionally left the safekeeping of
> passwords upon the server software (httpd). Which probably is the best,
> the other way around is *quite* harder to implement.

*ahem* You're completely forgetting about sniffing passwords
off the wire and DNS poisoning. This should be fixed in the
browser, and the correct fix is to nuke all password caching.
If there's a feature that makes life easier for Joe User, he
will use it, with no concern for security simply because he
didn't know there was a concern in the first place.



