I think The key reason why why this has altered is RFC 2616 assumed HTTP authentication can be applied when in exercise present-day Website apps Make custom made authentication strategies employing one example is varieties and cookies. They can use spy ware and infostealers to reap passwords or trick people http://pigpgs.com