Anyone here feel comfortable using standard HTTP usernames and passwords to control access to digital products on Web servers? I'm not talking about encrypted connections via SSL, I'm talking about being absolutely sure the username and password is the person you think it is. How do you know the user typing a username and password into your Web site is the person who purchased access to the products? continue
Reproduction in whole or in part in any form or medium without express written permission of Computerworld Inc. is prohibited. Computerworld and Computerworld.com and the respective logos are trademarks of International Data Group Inc.